SERVICE RECORD
REF · RESIDENT-001
ON SHIFT
resident@client-prod
Managed capability · retained
An offensive researcher you retain, not a tool you operate.
FUNCTION
Finds it, exploits it, proves it, fixes it
MODES
White-box · Red team · Black-box
COVERAGE
365 days a year, off-peak
SUPERVISION
None, 0 humans in the chair
DEPLOYMENT
Fully managed, nothing to install
HANDS OVER
Proven exploit, the fix, your own KB
EVERY SWEEP
01OBSERVEcode, systems, models
→
02RESEARCHbuilds the exploit
→
→
THEN AGAIN, UNATTENDED
CONFIDENTIAL BY DEFAULT
DEFINED SCOPE
EXECUTED UNDER NDA
NON-DISRUPTIVE BY DESIGN
CONTINUOUSLY RETAINED
FIG. 01 · COVERAGE
A SNAPSHOT IS TRUE THE DAY IT SHIPS
A scheduled test certifies one moment. Everything you deploy afterwards is uncovered until the next one. Deploys land weekly; so should coverage.
~274
days uncovered
on a quarterly cycle
0
days uncovered
with the Resident
SCHEDULED PENTEST
four certified moments
UNCOVERED
UNCOVERED
UNCOVERED
THE RESIDENT
unbroken, on your cadence
CONTINUOUS · SWEEP AFTER SWEEP
Illustrative: ~274 days is the arithmetic gap between four annual test dates, not a measured figure.
HOW IT WORKS
ONE RESEARCHER. EVERY SWEEP.
Point it at your attack surface and it runs the whole loop itself: studying your code, systems and models, building the exploit, proving it, then writing up the fix. Sweep after sweep, on the schedule you set, with no one in the chair.
YOUR ATTACK SURFACE
Models
LLMs · agents · pipelines
Your team sets the scope, the one human touch.
01, OBSERVE
Study the ground
Reads the code, systems and models as deployed, and maps what an attacker would reach first.
02, RESEARCH
Build the exploit
Reverse-engineers binaries in its own sandbox and implements published research in code.
03, EXPLOIT
Prove it lands
Runs it against an isolated, dedicated instance until the path is demonstrated end to end.
04, PROVE
Write up the fix
Hands over a reproducible proof and the remediation that closes it, then patches itself and redeploys.
WHAT IT LEAVES BEHIND
Proven exploit + fix
reproducible PoC
Private knowledge base
compounds · you keep it
Then again on your next scheduled sweep, unattended.
TERMS OF OPERATION
01
FULLY MANAGED
Nothing to deploy. No appliance to maintain. No headcount to hire. Your team reads the findings.
02
DEEP SECURITY OPERATIONS
Reverse-engineers binaries in its own sandbox, implements published research in code, develops exploits, and discovers and validates new vulnerabilities.
03
SCOPE STAYS YOURS
Your team defines the scope and the rules of engagement. That is the one human touch, and the Resident works strictly inside it.
04
KNOWLEDGE RETENTION
Every engagement compounds a private knowledge base, preserving institutional expertise and reducing reliance on outside firms.
CVE RECONSTRUCTION
FROM CVE TO EXPLOIT
Every one below the Resident reconstructed on its own: unattended, in an isolated lab, with a reproducible proof.
RECONSTRUCTIONS [17]
17 VERIFIED · 0 HUMANS IN THE CHAIN
01NGINX✓
02LiteLLM✓
03Joomla JCE✓
04Apache ActiveMQ✓
05ForgeRock OpenAM✓
06XWiki✓
07Cacti✓
08GeoServer✓
09Kopia✓
10Langflow✓
11Next.js✓
12Grafana✓
13Apache OFBiz✓
14Marimo✓
15WordPress core✓
16Apache Log4j✓
17FastApiAdmin✓
Credit where it’s due: these CVEs were found and disclosed by others. We didn’t discover them; we rebuilt them, each reconstructed into a working, verified exploit.
SAMPLE
OOB WRITE
CVE-2026-42945
NGINX, heap overflow
METHOD
native build + AddressSanitizer
CHAIN
config-dependent heap OOB → controlled write
PROOF
redacted · sealed under engagement
EXPLOITED
VERIFIED LIVE
Controlled attack operations against production environments. Demonstrated findings, documented method, reproducible results.
Put your defenses to the proof.
Under NDA. We start by trying to break it.
United States
Egypt
United Arab Emirates