Why random-mutation fuzzers lose coverage on structured protocols, and how to model a PDU with a grammar to systematically traverse field combinations. Covers And/Or combinatorial-explosion control, automatic boundary-value generation, automatic Size-field computation, and Lua-based checksum recomputation.
Multiple studies conclude that an LLM agent's completion bias and overconfidence cannot be corrected by prompting. This post lays out the design principles of a vulnerability-checking automation harness that makes "surveyed everything" and "0 vulnerabilities" computed from an HMAC receipt ledger and deterministic hooks rather than from the model's narrative. A "200 OK" without a negative control is not confirmation.
An anatomy of how Achilles Communications Certification (ACC) tests PLCs, RTUs, and industrial switches. It covers the classification of 31 L1 / 54 L2 test cases, the seven test types (Scans, Storms, Fuzzers, Grammars), control-protocol coverage from the IP stack up to DNP3, Modbus, and IEC 61850, and what the Normal/Warning/Failure monitors actually determine.
The architecture of a hierarchical multi-agent system that performs autonomous vulnerability assessment, from network reconnaissance to exploit validation. Seven specialists, a five-phase workflow, and the confirmation oracle, execution isolation, and RoE reference monitor that pull the judgment authority out of the model.
How a stack buffer overflow was found in the compression utility dact using AFL and AddressSanitizer. Root-cause analysis of a file_extd_urls array overflow triggered by a crafted DACT header.
A draft design for blackbox fuzzing of the LS Electric PLC system, built on analysis of the XGT protocol. Covers automated mutation strategy, crash triage, and the monitoring infrastructure for discovering vulnerabilities in industrial control systems.