Kernel & native security

Security testing for code that runs closest to the metal.

TraceFault is a specialist practice for Windows kernel drivers and native C++ applications — the software where a single missed check hands over the whole machine.

Remote engagements · NDA before scope · Reply within two business days

Why teams bring us in

Depth in one domain beats breadth in ten.

We only do this

No web apps, no compliance checklists. Kernel and native C++ is the entire business, so the hard part of your engagement isn't the part we subcontract.

Proof, not theory

Every finding is demonstrated on your build with working code. You get something your engineers can run, not a severity rating and a shrug.

Fixes that hold

A retest round is included in the fee. We review the patch itself, not just whether the original proof-of-concept stopped working.

Services

What we're brought in to do.

Four ways in, depending on where your software is and what's keeping you up at night.

Kernel driver auditing

A full attack-surface review of your WDM or KMDF driver, from the dispatch routines down. We assume the caller is hostile, unprivileged and patient.

C++ application review

Source-assisted review of native applications — memory safety, trust boundaries and the parsers that quietly accept whatever they're given.

Exploitability assessment

You have a crash and a deadline. We tell you whether it's a denial of service or a privilege escalation, and we prove which one it is.

Hardening review

Mitigations, build configuration and privilege boundaries assessed against how attackers actually work today — not against a 2015 checklist.

Expertise

Where the depth actually is.

01

Reverse engineering

Binary-only targets are normal work here. Source access widens coverage for the same budget, but it was never the requirement.

02

Fuzzing infrastructure

Harnesses built around your real entry points, tuned until they find things. You keep everything we build.

03

Memory safety

Lifetime bugs, allocation arithmetic and the races that only show up under load — the class of flaw that still carries most real-world impact.

04

Privilege boundaries

Everywhere a low-privileged process can reach something running as SYSTEM, and what it can do once it gets there.

Approach

A small team, and you work with all of it.

The person who scopes your engagement is the person who does the work. There's no bench of junior testers, no template report with your logo dropped into it, and nothing gets handed off halfway through.

Engagements typically run two to four weeks and are quoted as a fixed fee after scoping. Findings reach you as they're confirmed — anything critical the same day.

1

Scope

NDA, a call, and written authorisation naming the targets. We agree what a finding has to prove before anyone starts.

2

Test

Manual review alongside targeted fuzzing. Every candidate bug is driven until it either becomes a real primitive or gets ruled out.

3

Report & retest

A written report, a walkthrough with your engineers, and one retest round once your fixes ship. The retest is included.

Contact

Let's talk about your scope.

Tell us what you've built and what worries you about it. A scoping call costs nothing.

contact@tracefault.dev

We test only systems our clients are authorised to have tested, under written authorisation naming the targets.

No tracking or analytics on this page.