Offensive Security Research · Since 2017

Blackstorm Security is a boutique research firm specialized in vulnerability research and exploit development against iOS, Android, Google Chrome, Windows and hypervisors — and we teach the same discipline we practise. Our training has become the reference in the field.

Capabilities

What we do

Original research first. Everything else we offer is built on the same low-level expertise.

Training

Learn to break what everyone else trusts

More than twenty deeply technical courses in vulnerability research, exploit development, reverse engineering and malware analysis — taught by researchers who are actively doing this work, not describing it. Online or in-person, in English or Portuguese, with certification for completed tracks.

Research

The work behind all of it

Our services and our courses come from the same place: original research, published openly and free of charge. Nothing we teach or deliver is theory we have not practised ourselves. These are the most recent releases — open any card for the full briefing and the PDF.

ERS 09 · 106 pages

Exploitation Techniques | CVE-2024-30085 (part 03)

Closes the CVE-2024-30085 exploitation arc with two editions that move beyond token stealing and I/O Ring. The PreviousMode edition flips a single byte in …

ERS 08 · 91 pages

Exploitation Techniques | CVE-2024-30085 (part 02)

Focuses exclusively on two further I/O Ring exploit variations against the same cldflt.sys vulnerability. Technique 02 uses I/O Ring for both read and write, …

ERS 07 · 119 pages

Exploitation Techniques | CVE-2024-30085 (part 01)

Continues the cldflt.sys minifilter analysis begun in ERS 06, reusing the same n-day as a reference platform for new exploitation techniques rather than introducing …

ERS 06 · 296 pages

A Deep Dive Into Exploiting a Minifilter Driver (N-day)

A fully practical, end-to-end exploitation of a real Windows minifilter driver: CVE-2024-30085, a heap buffer overflow in cldflt.sys fixed by KB5039212. It covers …

ERS 05 · 57 pages

Hyper-V (part 01)

The first installment of a multi-part series on hypervisors, establishing a working understanding of hypervisor concepts using Microsoft Hyper-V as the reference …

ERS 04 · 126 pages

macOS/iOS (part 01)

An introductory review of macOS and iOS internals aimed at vulnerability research. It covers acquiring and unpacking IPSW firmware, extracting and parsing the …

ERS 03 · 62 pages

Chrome (part 01)

An introductory, step-by-step study of Google Chrome and in particular its V8 JavaScript and WebAssembly engine. It covers building V8 and the d8 shell from source …

ERS 02 · 85 pages

Windows Kernel Drivers (part 02)

A step-by-step patch-diffing walkthrough built around CVE-2022-35804, the SMB Client and Server remote code execution vulnerability. It documents the full workflow: …

2017
Researching since
20+
Technical courses
8
Certifications
5
Platforms researched
Work With Us

Bring us the problem nobody else could solve

Scanners produce findings. Finding a vulnerability nobody has found before, proving it is exploitable, and understanding exactly what an attacker could do with it is a different discipline — and it is the only one we practise.

If your problem needs researchers rather than a report, we should talk. Every engagement is scoped individually and handled with complete discretion.