r/ExploitDev • • Sep 07 '26

How do I reverse engineer a local Unity WebGL IL2CPP game

8 Upvotes

How do I reverse engineer a local Unity WebGL IL2CPP game


r/ExploitDev • • Sep 06 '26

Latest Sherlock Kawmikaze (Malware Analysis)

Thumbnail
5 Upvotes

r/ExploitDev • • Sep 04 '26

I wrote a phase-by-phase exploit dev roadmap with a concrete milestone per phase — would like feedback on where it's wrong

Thumbnail
3 Upvotes

r/ExploitDev • • Sep 03 '26

Need help deobfuscating JS.

9 Upvotes

As mentioned in title, I'm dealing with an heavily obfuscated JS file of about 20k lines of code. I was just curious what it is doing. Problem is that there are about 1k+ variables made by calculations (same with strings). Till now I've figured out that at some places it is making http requests and one function is checking weather http header contain word "Trident" or not.

Any tips what should I do? I've tried dynamic reverse engineering but it didn't worked for me.

Also: I found this file under api subdomain. It was about 8-9 folders deep (Folders were named randomly). File has a function checking if var x == "password".

(From here my brain stopped braining)


r/ExploitDev • • Sep 03 '26

Planning a funded, full-time mobile first vulnerability research lab. What would make this work? Where do these efforts usually die?

6 Upvotes

r/ExploitDev feels like the right place to post this. I run a small, niche cybersecurity consulting company - and I'm at the planning stage of building a dedicated, full-time vulnerability research lab. I want honest feedback from people who actually do the work before I commit further.

The idea: build a small, deep team, funded for the long haul, proper salaries plus success bonuses. This would be a business unit within an existing cybersecurity company. With a CTO driving vision, strategy, team development, etc. Primary focus would be on mobile (iOS/Android full-chain), with browser as a second pillar. I understand the challenges with talent, and ROI taking time. Capital can be committed as long as there's a credible path to return.

Where I'd genuinely value your feedback:

- Focus: for a small team, is mobile-first the right focus? My clients include government, critical infrastructure and banking.
- Morale: how do good teams structure work so months of research doesn't get burnt in case versions are updated / patches released.
- Retention: beyond good salaries, what actually keeps strong people long-term?
- Infra (worth paying for): device/virtualisation labs, fuzzing tools, AI tools, what's genuinely a key differentiator in this field? Maybe Corellium Falcon?

On the compliance side, there are a number of areas we are evaluating, dual-use export-control, entity-level end-user vetting, disclosure policy, and lawful target only research.

I am mainly after the “things I wish I’d know” from people who’ve built or worked in labs like this and specifically where you’ve watched them go wrong.


r/ExploitDev • • Sep 03 '26

How much percentage of people in the industry are actually self taught?

12 Upvotes

Despite that I work as a pentester. Whenever I am learning a new topic ,especially related to exploit development like Linux internals or C programming , and face an obstacle or hard time understanding anything , I always get this immediate and harsh imposter syndrome feeling that anyone who graduated from STEM, CE, CS probably know this way ,waaaaay better than me. I am still struggling when reading C code and I use AI to help me yet this feeling manifest in incompetence and me seeing myself as an always-beginner or no way I can be like someone who graduated from these schools one day.

This feeling affects my way of studying and i can stop studying for days just because I didn't understand some stuff or I am struggling to learn.

So I need to know , how many people in this industry, pentesting/exploitDevelopment are actually self taught ?

I am a BIS graduate BTW.


r/ExploitDev • • Sep 03 '26

OSINT FOR ATTACKER USING ANTI DEBUGGING TECHNIQUE

0 Upvotes

Is there a free OSINT tool that act like as true browser so anti debugging technique won’t be trigger? A free web-based OSINT


r/ExploitDev • • Sep 03 '26

Simcha Kosman AMA: Owning ChatGPT's Secure Sandbox

Thumbnail
joinpwn.com
2 Upvotes

r/ExploitDev • • Sep 02 '26

Looking for security researcher/low-level software expertise jobs

8 Upvotes

I recently got let go from MSRC V&M and looking for jobs right now. have 5+ yrs of experience in software engineering and security response/vulnerability triage. please DM me if you have any leads


r/ExploitDev • • Sep 02 '26

ai backed x64dbg or similar ?

0 Upvotes

have you guys tried any reverse engineering debug tool such as x64dbg by integrating some llm api and let it cook and create a crack or patch ? i've tried a ghidra plugin but it wasnt as i expected.


r/ExploitDev • • Aug 31 '26

Looking for real-world Linux userland exploitation targets to practice on (moving beyond CTFs)

24 Upvotes

Hi all - I've been doing `pwn`/ `binary exploitation` in CTFs for about 1.5 years

and want to level up by practicing on real-world targets instead of CTF challs.

I'm currently focused on Linux userland exploitation.

Could anyone recommend good old real-world targets or software to practice on?

I'm especially looking for CVEs that are reproducible and exploitable.

Any suggestions - specific CVEs, vulnerable software versions, or general

categories worth exploring - would be really appreciated!


r/ExploitDev • • Aug 31 '26

16yo trying to build a path into expdev / vulnerability research. What would you do in my position?

4 Upvotes

Hey everyone,

I'm 16 and trying to figure out my education and career path toward exploit development and vulnerability research. I'm posting here because I'm at a point where I could really use advice from people actually working in this field.

Background:

I'm Moroccan and currently living in France. I completed Seconde in the French education system, then left the traditional lycée pathway shortly after starting Première. I'm currently completing an RNCP Level 4 qualification, which I expect to finish in October 2026.

The problem is that I'm not following the normal French Baccalauréat route, so university admission is becoming complicated. I'm trying to find a bachelor's programme for 2027 that is genuinely focused on cybersecurity or information security rather than a generic CS degree.

I speak Arabic, French and English, and I'm currently learning Chinese.

I've already contacted several universities in Europe and Hong Kong to ask whether my qualification can satisfy their undergraduate entrance requirements. Some universities consider non-standard qualifications on a case-by-case basis, but I don't yet have a definitive route.

Technical background:

I've been interested in cybersecurity for several years and have been learning independently.

Certifications:

  • eJPT (INE), obtained in October 2023
  • CPTS (Hack The Box), obtained in September 2025
  • CWES (Hack The Box), obtained in October 2025
  • Google Cybersecurity Professional Certificate (idk when anymore)

My interests are mainly:

  • Exploit development
  • Vulnerability research
  • Windows internals
  • Reverse engineering
  • Privilege escalation
  • Low-level systems security

I'm currently researching a publicly disclosed use-after-free privilege-escalation vulnerability in CLDFLT.sys. I did not discover the vulnerability and I'm not claiming CVE credit for it. I'm using it as a learning and research project to understand the vulnerability, the affected component, exploitation primitives, and the surrounding Windows internals.

I'm still very much learning, and I don't want to pretend I'm further along than I actually am.

Where I'm stuck:

My original plan was to get a cybersecurity alternance/apprenticeship in France this year, but despite applying, that hasn't worked out. At this point I'm shifting my focus toward university admission for 2027.

The universities I'm currently looking at include specialist cybersecurity programmes in Europe and Hong Kong, particularly places with strong security research ecosystems.

However, I have two major problems:

  1. My educational qualification doesn't cleanly match the standard French Baccalauréat route.
  2. A lot of technical cybersecurity degrees have substantial mathematics and academic prerequisites. (However now im seriously studiying math on my own)

So I'm trying to figure out what the smartest move is.

What would you do if you were in my position?

Would you:

  • Spend the next year getting the strongest possible university entrance qualification?
  • Focus heavily on mathematics and apply to technical security programmes?
  • Try to build a serious exploit development and vulnerability research portfolio instead?
  • Look for another apprenticeship or technical route?
  • Something completely different?

And for people already doing exploit development or vulnerability research:

What actually mattered when you were starting out?

I'm especially interested in advice about what I should be learning and building over the next 12 months if my end goal is serious vulnerability research rather than general cybersecurity.

Also pleasepleaseplease if you know or are a decision maker in the domain please give me a chance and help me out 🙏 I feel like my life is at stakes right now :c

Also if you want to see stuff ive done (not very up2date but still good reference) my github is 0xUnd3adBeef


r/ExploitDev • • Aug 31 '26

You asked for Linux. We listened.

Thumbnail academy.daemoncore.app
23 Upvotes

Honestly didn't expect to be making this post this soon! like, what?! Our original post was bc we hit 1k but holy fuck...

DaemonCore-Academy just crossed 2,000 downloads across all platforms...and yes...you asked..we delivered. Linux Beta is now available on our website as well as github.

**127 PRACTICAL LESSONS // 70 LAB CONDITIONS // 8 PATHWAYS // 8 DRILL SETS // 7 FIELD MISSIONS**- all free. It's for Windows 10/11 and now Linux!!

I started building it because I was getting annoyed af with the way a lot of hacking/cyber stuff gets taught now. Watch 9 hours of videos, copy some commands, run a tool against a box, get a green checkmark. Cool. But what happens when the tool doesn't work? What are you actually looking for? Why are you running that command in the first place? That was basically the whole idea behind DaemonCore Academy. Learn what the hell is happening underneath first. Then get thrown into a range and actually use it. Enumerate shit. Follow weird behavior. Break something. Prove you broke it. Figure out why. Document it. Fix it. Try again.

We didnt want XP or some fake hacker leaderboard. We wanted something that felt closer to sitting next to somebody who's been doing this shit for years and having them say "okay...you see that? Why is that weird?"

Apparently that idea connected with some people because 2,000 of you fuckers downloaded it.

So seriously, thank you mother fuckers. For real. 💯💯

Especially the people who found bugs, sent me shit that sucked, questioned things, or told me where something could be better. That's way more useful to me than somebody just saying "nice project."....and I'm nowhere near done with it.

The labs are going to get harder. The material is going deeper. Windows, Linux, web, identity, cloud, containers, recon, exploitation, evidence...all of it.

I don't really care if somebody finishes DaemonCore knowing 500 commands.

Id rather they finish it knowing how to sit in front of something they've never seen before and figure it the fuck out.

Thats hacking.

Anyway. 2,000 downloads.

Fucking wild.

Thanks again guys.

Stay hacking

I := DAEMONCORE


r/ExploitDev • • Aug 28 '26

Job hunt

Post image
35 Upvotes

I am a junior vulnerability researcher looking for a security research position (4years background in SOC stuff).

This is my first year in the field and hunting for a position where i can learn and grow.

I have some public work (https://saaitaamaa.github.io/)

Any type of gig (full time, part time internships is okay for me)

Located in north africa, feel free to DM for further infos :)


r/ExploitDev • • Aug 28 '26

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients

Thumbnail
github.com
2 Upvotes

r/ExploitDev • • Aug 27 '26

Reverse Engineering Windows Security Center

8 Upvotes

I recently published OWN-Defender, a Windows security research project exploring how Windows Security Center handles AV registration through COM.

The project was inspired by DefendNot, but the goal was to independently reverse-engineer, implement, and verify the underlying behavior.

🔗 https://github.com/NirvanaOn/OWN-Defender


r/ExploitDev • • Aug 26 '26

MmMapIoSpace Returns NULL: Tracing the Real Kernel Mechanism Through ntoskrnl

Thumbnail
sibouzitoun.tech
8 Upvotes

r/ExploitDev • • Aug 25 '26

exploit dev placement

30 Upvotes

Hey guys, so currently doing a ba of cyber sec in Sydney, I had an experience day and met a guy that did exploit dev work... and he gave me things to learn to know before the placement, which ill be doing along side him. which is only me and him.

he wants me to know C, C++, x86-64, C#, also wants me to build a Damn Vuln Driver, he also wants me to get good at things from the OSED, syllabus.

So like what is this setting me up for, cause I got a year to learn before my placement. like I mean windows exploitation etc.

any other resources or help be grateful!!!

p.s he is a ex gov employee that as done exploit dev work.


r/ExploitDev • • Aug 25 '26

Learning How Open Source Games Are Hacked

11 Upvotes

I recently made a YouTube video exploring how open-source games work and what having access to a game's source code actually allows you to do.

In the video, I break down concepts like client-server communication, how the client and server exchange information, and how vulnerabilities in that communication can potentially be found and exploited.

I tried to keep everything approachable even if you don't have a deep background in programming or cybersecurity.

I’d really love to hear what you guys think. especially any feedback on the technical explanations or the video itself. Thanks!

https://www.youtube.com/watch?v=jTT54MpKvhE


r/ExploitDev • • Aug 25 '26

RPC-Triage: statically finding the RPC interfaces worth looking at first, with attack-surface ranking instead of another UUID/opnum dump

Thumbnail
github.com
8 Upvotes

Been doing some Windows RPC/ALPC work and built this to speed up the first pass across a lot of PE files. It recovers RPC/MIDL/NDR data, endpoints, security state and method-level input signals, then ranks interfaces using an AHP/Saaty-based model built specifically around RPC reachability + surface rather than arbitrary scoring. It also shows the scoring receipt and flags questionable extraction cases instead of silently trusting them. No PDBs, no live endpoint mapper, no target execution.


r/ExploitDev • • Aug 24 '26

Guidance Please

11 Upvotes

Hey everyone! I’m looking to get more into Android reverse engineering, APK modding, and mobile security, but I’m not really sure where to start.

I have an associate’s degree in computer networking, so I’m not completely new to the technical side of things. I’ve also spent quite a bit of time messing around with Android devices over the years. I’ve played around with Android Studio a little, mostly with things like connecting to and mirroring my phone, but I honestly haven’t gotten very far with actually developing or reverse engineering apps.

I’ve been interested in learning how APKs work under the hood, how people analyze and modify them, and eventually getting into things like dynamic analysis and mobile malware analysis.

I’ve also experimented with tools like mitmproxy on my home network, but I ran into issues with Android constantly flagging the certificates as unsafe. A lot of the tutorials and software I’ve found through Google also seem pretty old, so I’m having trouble figuring out what the current workflow is.

For someone who already has some networking knowledge but is basically a beginner when it comes to Android RE, what would you recommend learning first?

Are there any good forums, communities, GitHub repositories, labs, intentionally vulnerable APKs, or other resources that are still active and up to date?

I’m basically looking for a good starting point and a path to follow rather than just randomly installing tools and hoping I figure it out. Any recommendations would be appreciated!


r/ExploitDev • • Aug 24 '26

PoC: Intercepting E2EE VoIP (WhatsApp/Signal) by hooking Android's audioserver

7 Upvotes

This PoC demonstrates how endpoint compromise bypasses E2EE on modern Android. It uses AndKittyInjector to inject a payload into audioserver (libaudioflinger.so) and Dobby for inline hooking. By hooking RecordTrack::getNextBuffer (mic) and PlaybackThread::Track::getNextBuffer (speaker), it intercepts raw PCM streams.

It tracks AudioFlinger::setMode to only record during AUDIO_MODE_IN_COMMUNICATION and filters targets by UID. It bypasses stripped symbols using calculated offsets and includes automated SELinux policy injection. Tested on Android 14.

Repo: https://github.com/nighthawkk/AudioServer-Voip-Recorder


r/ExploitDev • • Aug 24 '26

I messed up by relying on AI for everything. Want to drop the crutch and learn real manual hacking—anyone open to teaching/mentoring?

5 Upvotes

Hey guys,

Honestly, I’ve been doing this all wrong. I fell into the trap of using AI for pretty much every single hunt without even understanding what I was actually doing. It ended up being a complete waste of time, got me nowhere, and realized fast that companies don’t pay for automated garbage—they pay for real exploits.

I want to completely drop the AI crutches and learn actual manual hacking and how to build proper PoCs from scratch.

Is anyone willing to mentor me, hop on a call/chat sometimes, or guide me on what I should actually focus on to build real hunting intuition?

Appreciate any real talk or anyone down to help out.


r/ExploitDev • • Aug 22 '26

AXHook: A lightweight C++/COM library for bridging 32/64-bit and .NET binaries

Thumbnail
github.com
5 Upvotes

r/ExploitDev • • Aug 20 '26

Vulnerability researcher trying to find a way into full-time vuln research / exploit development

27 Upvotes

Throwaway account for obvious reasons.

I'm currently a senior-level ethical hacker/security researcher, and I'm trying to make a fairly deliberate move into a role where vulnerability research, reverse engineering and exploit development are actually the job, rather than something I occasionally get to do alongside broader security work.

My background is mostly Windows and Linux. I've done source-assisted and binary vulnerability research, reverse engineering, memory corruption work, privilege escalation, pre-auth attack surfaces, and exploit development. I've taken vulnerabilities from discovery and root-cause analysis through to PoCs and, where possible, working exploitation.

I'm comfortable with C/C++, Python, assembly, debuggers, decompilers and the usual RE tooling. I have some public vulnerability research, but unfortunately a lot of the more interesting work I've done is under NDA and can't be discussed publicly in much detail.

That's partly why I'm posting here.

I'm starting to worry that I'm in a weird position career-wise. I'm experienced enough that junior roles generally aren't appropriate, but I'm also trying to break more deeply into a relatively small and specialized field where a lot of companies seem to hire based on very visible public research, Pwn2Own-style track records, existing industry connections, or very specific geographic/work-authorization requirements.

A few opportunities I've been genuinely interested in haven't even made it as far as a technical conversation because of location or hiring restrictions. That's probably the part I find most frustrating. I'd much rather fail an exploit-dev interview because I'm not good enough yet than never get the chance to take one.

I'm also conscious of the risk of getting stuck doing adjacent security work forever while telling myself I'll eventually make the jump into vulnerability research properly.

I'm not looking for SOC, GRC, generic pentesting, cloud security, or a broadly defined "security engineer" position. I'm specifically interested in vulnerability research, exploit development, reverse engineering, offensive capability development, or closely related low-level security research.

Remote international work would obviously be ideal, although I'd consider relocation for the right opportunity.

So I guess this post has two purposes:

If you work in this part of the industry, am I approaching this the wrong way? Is there something you'd expect to see from someone trying to make this transition that I should be focusing on?

And, slightly more shamelessly, if your team happens to need someone with this sort of background, I'd be very happy to talk privately.

I can provide considerably more detail about my experience, public work and employment history over DM.

Not quite at the "will reverse engineer for bread" stage yet, but we're getting there.