Reverse engineering · Vulnerability research

Security research for complex software and hardware. Expertise-driven, machine-accelerated.

Vici Labs is a boutique software and hardware research lab, working at the lowest levels of the stack for teams that need ground truth — not guesswork.

Get in touch veni · vidi · vici
01

Capabilities

We take on the work most teams don't keep in-house: closed systems, undocumented software, and the bugs that only surface once you dig deep.

Binary

Reverse Engineering

Software, firmware, drivers, and closed protocols taken apart.

Engineering

Custom Tooling & Software

Purpose-built tools: hooks, injectors, and protocol sniffers — bespoke software for the target at hand.

Discovery

Vulnerability Research

Memory-safety and logic flaws found through targeted review and analysis.

Offense

Exploit Development

Proof-of-concept exploits and mitigation bypasses that demonstrate real, reproducible impact.

Silicon

Hardware & Embedded

Physical attacks on embedded and IoT devices — debug ports, flash extraction, and fault injection.

Analysis

Malware & Threat Research

Unpacking, behavioral analysis, and capability assessment of implants and loaders, combined with post-incident digital forensics.

02

Method

Every engagement runs the same disciplined arc — acquire the truth, understand it completely, then prove it beyond doubt.

veni / I came

Access & ground truth

We acquire the target, instrument it, and establish exactly how it behaves in reality — not how the datasheet claims it does.

vidi / I saw

Analysis

Static and dynamic reverse engineering until the system holds no more surprises. Hypotheses are tested against the machine, never assumed.

vici / I conquered

Proof & handover

Proven findings, working proofs-of-concept, and clear remediation. If we can't demonstrate it on the real target, we don't report it.

03

Ethos

A lab, not an agency. Senior researchers only, discretion by default, and work measured by what we can actually prove.

01

Senior hands, always

The people you scope with are the people doing the work. No juniors staffed onto your target to learn on the job.

02

Discretion is the default

NDA-first engagements. Findings, tooling, and the fact that we worked together stay between us — permanently.

03

Proof over speculation

We don't ship maybes. A vulnerability isn't real to us until it runs against the actual system.

04

Human-led, tooling-amplified

Custom harnesses, emulation, and automation extend our reach — but the judgment behind every finding is a researcher's.

04

Start a conversation

Firmware you can't get answers about, making a program do things it was never meant to do, or a bug you need chased to the bottom — reach out and we'll take it from there.

No web forms, no trackers. PGP key available on request.