01
Web applications
& APIs
Authorization failures, workflow abuse, state transitions, and multi-step logic flaws that scanners and isolated tests tend to miss.
Independent offensive security research
I test web applications, APIs, and AI-enabled products, with a focus on authorization boundaries, business logic, and unsafe agent behavior.
Manual testing
Targeted automation
Reproducible evidence
01 / Focus
A deliberately narrow practice centered on complex trust boundaries—not a checklist of every security discipline.
01
Authorization failures, workflow abuse, state transitions, and multi-step logic flaws that scanners and isolated tests tend to miss.
02
Agent and tool boundaries, prompt injection paths, untrusted context, data exposure, and the application behavior surrounding the model.
03
Purpose-built recon, source-assisted review, and small automation systems that expand coverage without replacing human judgment.
02 / Method
Map actors, assets, state, and trust boundaries before sending payloads.
Test how components behave when identity, sequence, and context stop matching expectations.
Reduce the issue to a safe, repeatable path with clear technical and business consequences.
Deliver evidence, reproduction steps, affected boundaries, and practical remediation context.
03 / About
I’m Knox, an independent offensive security researcher working across web applications, APIs, and AI systems. I’m interested in the failures that appear between components: identity assumptions, hidden state, unsafe delegation, and business rules that do not survive adversarial use.
Automation is used to widen coverage and make results repeatable. The actual research remains driven by system understanding, careful testing, and clear evidence.
Available for select private programs, focused assessments, and research collaboration.
04 / Contact
Send the target context, desired outcome, and timeline. Sensitive details can follow over an agreed secure channel.
cve@knoxlab.co