Research lab · building in the open

Offensive security research,
engineered in the open.

We publish original offensive security research, open-source tooling, exploit development resources, and technical writeups focused on Windows internals, reverse engineering and modern cybersecurity.

researcher@beaconbytes ~/labs/pe-parser
zsh
$ ./analyze sample.exe
[+] Parsing PE headers
[+] Found 12 sections
[+] Extracting imports  ·  214 symbols
[+] Mapping section permissions
[+] Generating report → report.json
[+] Analysis complete
$ _
Latest Research

Writeups, primitives and post-mortems.

Peer-reviewed internally. Reproducible. Published without embargo when possible.

No featured posts yet. Mark a post as "Feature on homepage" in the admin editor to pin it here.
Featured Tool
No featured tools yet. Add one from /admin/tools and toggle "Feature on homepage".
Focus Areas

Where we spend our cycles.

Six research tracks, aligned around real adversary tradecraft and defender needs.

Exploit Development

Memory corruption, logic flaws, primitive crafting and modern mitigation bypasses.

Windows Internals

Kernel, drivers, ETW, WFP, PatchGuard, and the undocumented surface underneath.

Reverse Engineering

Static and dynamic analysis of binaries, protocols, obfuscators and firmware.

Malware Analysis

Unpacking, IOC extraction, capability mapping and threat actor attribution.

Web Security

Server-side logic bugs, deserialization, prototype pollution and modern SSRF.

Security Tooling

Purpose-built open-source tools for researchers, red teamers and defenders.

About the lab

Research first.
Marketing never.

BeaconBytes is a small collective of engineers, exploit developers and reverse engineers building tooling and publishing writeups we wish existed when we started. Everything we ship is auditable, and most of it is open source.

Depth over volume
Reproducible
Engineer-owned
Read our philosophy