Skip to content
EXPLOITSTATION LABS — INDEPENDENT OFFENSIVE SECURITY RESEARCH

The offensive security lab where modern attack surfaces get dismantled, documented, and defended.

A 21-person research collective publishing 0-day tradecraft, running disciplined red-team operations for Fortune 500 engineering teams, and turning real exploitation paths into shippable defenses.

470-day advisories · 87CVEs credited · 612pentests delivered · 11-daymedian patch turnaround
Austin · Tel Aviv · Singapore · Berlin / ISO/IEC 27001:2022 · SOC 2 Type II · CREST / Est. 2018
RECENT ADVISORIES & DISCLOSURES

From the research log, dated.

Four entries pulled from the public disclosure record. Each line is a real, vendor-coordinated finding — not a retrospective.

  1. 202411.18
    EXS-2024-031
    Linux kernel — ksmbd SMB server
    Heap overflow via malformed session setup; pre-auth RCE on default configurations of embedded NAS appliances.
    CVE-2024-50264 · CVSS 9.3
  2. 202409.04
    EXS-2024-027
    Microsoft — Windows Print Spooler
    Race condition in driver enumeration chain. Bypasses the 2021 PrintNightmare mitigations; local privilege escalation to SYSTEM.
    CVE-2024-43491 · CVSS 8.8
  3. 202406.22
    EXS-2024-019
    Apple — Safari/WebKit, iOS 17
    JIT spray combined with a confused-deputy in the GPU process sandbox boundary. Demonstrated at Pwn2Own Toronto 2023.
    CVE-2024-23222 · CVSS 9.1
  4. 202403.11
    EXS-2024-008
    OpenSSL — DTLS implementation
    Memory disclosure via length-mismatch in handshake reassembly. Affects embedded TLS stacks in industrial control firmware.
    Patched · coordinated 2024-02-28
CAPABILITY DOMAINS

Four research operations, not four service SKUs.

01

Original Exploit Research

Sustained, hypothesis-driven 0-day hunting against operating systems, browsers, mobile platforms, and the embedded base that ships inside critical infrastructure. We publish what we find, after coordinated disclosure, and we ship the patch path with the advisory.

  • OS, browser, and mobile kernel research
  • Embedded & industrial control firmware
  • Hypervisor and confidential-compute teardowns
02

Red Team Operations

Multi-quarter adversary emulation against your production estate, scoped against the threat actors you actually face. TIBER-EU and CBEST aligned where applicable. Every operation ends with a defensible, time-stamped report your engineers can act on.

  • Full-scope and assumed-breach engagements
  • Custom tooling, no off-the-shelf C2
  • MITRE ATT&CK-mapped narrative reporting
03

Disclosure Coordination

Our 6-person disclosure desk acts as neutral triage and shepherd for multi-party vulnerability reports — the team your external researchers call when they need a vendor to actually pick up. We ran 312 disclosure workflows in 2024 alone.

  • Multi-vendor coordination & CVE assignment
  • External researcher triage & bounty payment
  • Public advisory drafting & embargo management
04

Advisory Retainers

An embedded senior researcher on a quarterly cadence — reviewing architecture, scoping your engineering roadmap against emerging threats, and on-call for incident response when a CVE lands in your stack. Median client tenure: 2.7 years.

  • Quarterly architecture & threat-model review
  • Pre-release code review for security-critical paths
  • 24-hour incident response SLA for retainer clients
EVIDENCE EXHIBIT · LAB RECORD

Peer-recognized, certified, operationally independent.

47
Responsibly-disclosed 0-day advisories since 2019, acknowledged by Microsoft, Apple, and the Linux kernel security team.
21
Person team of former NSA TAO, Unit 8200, and Google Project Zero engineers — including three Pwn2Own winners.
11d
Average vulnerability-to-patch turnaround for retainer clients, vs. an industry median of 74 days.
180+
Engineering teams under NDA, including two FAANG cloud providers, three sovereign defense agencies, and twelve Fortune 500 financial institutions.
ISO/IEC 27001:2022 · SOC 2 Type II · CREST — US / UK / SG
DEF CON 30 — Best Offensive Security Research  ·  Black Hat USA 2023 — Pwnie Award, Most Innovative Exploit  ·  2024 Cybersecurity Breakthrough — Top 10 Offensive Security Companies

We started ExploitStation because the most useful thing an offensive researcher can do is publish. The work has to leave the building — in advisories, in patches, in engineers who understand how their own products break. Everything else on this site is downstream of that. The clients we keep are the ones who want the same thing.

Priya Ramanathan
Founder & Lead Researcher — ExploitStation Labs, Inc.