Web applications
Manual testing of application logic, authentication, authorization, sessions, and the assumptions scanners miss.
Independent offensive security practice
Nyx Labs breaks assumptions, traces attack paths, and hardens the systems your organization cannot afford to lose.
Adversary simulation · Application security · Security engineering
01 / Services
Offense reveals where trust breaks. Defense makes that knowledge durable. We work across both so findings become stronger systems—not abandoned reports.
Human-led assessments that follow real attack paths, prove impact, and give your team a clear route to remediation.
Manual testing of application logic, authentication, authorization, sessions, and the assumptions scanners miss.
iOS and Android assessment across the client, local storage, transport, platform controls, and supporting services.
Deep review of REST, GraphQL, and service interfaces with emphasis on access control, data exposure, and abuse paths.
External and internal infrastructure testing that maps reachable assets, weak trust boundaries, and viable attack chains.
Identity and domain security assessment covering privilege paths, delegation, policy, credentials, and lateral movement.
Broad, objective-led testing across identity, endpoints, cloud, SaaS, networks, and the seams between them.
Threat-informed simulations that exercise people, process, and technology against realistic attacker behavior.
Continuous visibility, specialist investigation, and security engineering built around the systems you actually operate.
Around-the-clock detection, triage, escalation, and response support tuned to the signals that matter to your environment.
Static and dynamic analysis that explains capability, behavior, indicators, and practical containment options.
Evidence-led review of controls, architecture, operations, and risk with findings teams can act on.
Purpose-built detection, automation, research, and security tooling when off-the-shelf software does not fit.
02 / Method
No mystery dashboard. No hundred-page export. You work directly with the people doing the testing, from first hypothesis to verified fix.
We define the real assets, likely adversaries, and conditions of failure.
We test the paths that matter with disciplined, human-led offensive work.
Findings arrive with reproducible evidence, exploit narratives, and impact.
We stay close through remediation and verify that the fix survives contact.
03 / About
Nyx Labs is an independent security practice built for organizations whose products, infrastructure, and users cannot be treated as abstractions.
We work quietly, communicate plainly, and stay close to the technical truth. Our research continues beyond client work through coordinated disclosure and original security tooling.
We are trusted by
Responsible disclosure
additional findings under responsible disclosure
04 / Blog
Research notes, defensive patterns, and lessons from the systems we are permitted to discuss.
05 / Contact
Tell us what matters, what changed, and what you do not yet trust. We will tell you plainly whether we are the right people for the work.