Independent offensive security practice

We find the breach before it finds you. 

Nyx Labs breaks assumptions, traces attack paths, and hardens the systems your organization cannot afford to lose.

Begin an assessment

Adversary simulation · Application security · Security engineering

01 / Services

Security from both sides.

Offense reveals where trust breaks. Defense makes that knowledge durable. We work across both so findings become stronger systems—not abandoned reports.

01

Offensive security

Human-led assessments that follow real attack paths, prove impact, and give your team a clear route to remediation.

Web applications

Manual testing of application logic, authentication, authorization, sessions, and the assumptions scanners miss.

Mobile

iOS and Android assessment across the client, local storage, transport, platform controls, and supporting services.

APIs

Deep review of REST, GraphQL, and service interfaces with emphasis on access control, data exposure, and abuse paths.

Network

External and internal infrastructure testing that maps reachable assets, weak trust boundaries, and viable attack chains.

Active Directory

Identity and domain security assessment covering privilege paths, delegation, policy, credentials, and lateral movement.

Enterprise

Broad, objective-led testing across identity, endpoints, cloud, SaaS, networks, and the seams between them.

Adversary emulation

Threat-informed simulations that exercise people, process, and technology against realistic attacker behavior.

02

Defensive security

Continuous visibility, specialist investigation, and security engineering built around the systems you actually operate.

24/7 SOC monitoring

Around-the-clock detection, triage, escalation, and response support tuned to the signals that matter to your environment.

Malware analysis & reverse engineering

Static and dynamic analysis that explains capability, behavior, indicators, and practical containment options.

Information security audits

Evidence-led review of controls, architecture, operations, and risk with findings teams can act on.

Security software & custom tools

Purpose-built detection, automation, research, and security tooling when off-the-shelf software does not fit.

02 / Method

Quiet process. Severe attention.

No mystery dashboard. No hundred-page export. You work directly with the people doing the testing, from first hypothesis to verified fix.

  1. 01

    Frame

    We define the real assets, likely adversaries, and conditions of failure.

  2. 02

    Enter

    We test the paths that matter with disciplined, human-led offensive work.

  3. 03

    Prove

    Findings arrive with reproducible evidence, exploit narratives, and impact.

  4. 04

    Harden

    We stay close through remediation and verify that the fix survives contact.

03 / About

Trust earned under pressure.

Nyx Labs is an independent security practice built for organizations whose products, infrastructure, and users cannot be treated as abstractions.

We work quietly, communicate plainly, and stay close to the technical truth. Our research continues beyond client work through coordinated disclosure and original security tooling.

We are trusted by

  • AMD
  • BugForge
  • Meta
  • Google
  • TRON
  • NASA
  • Linktree
  • Vercel
  • GitLab
  • GitHub
  • NVIDIA
  • SKALE Networks
  • Chime
  • Coinbase

Responsible disclosure

Research that improves the commons.

Published CVE-2025-59843 Published CVE-2025-59932
In coordination 06

additional findings under responsible disclosure

04 / Blog

Signals from the field.

Research notes, defensive patterns, and lessons from the systems we are permitted to discuss.

View all writing

05 / Contact

Bring us the system that keeps you awake.

Tell us what matters, what changed, and what you do not yet trust. We will tell you plainly whether we are the right people for the work.

[email protected]

PGP available on request · Response within two working days