Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →

Most security consultants
have never found a CVE.

traztech's principal, Jacob Masse, is a security researcher with five published CVEs and responsible disclosures. One of them, CVE-2024-45163, is a CVSS 9.1 kill-switch for the Mirai botnet that CyberInsider wrote up. That is the offensive-security depth behind every engagement we run.

The Mirai botnet kill-switch

Published CVEs & disclosures

CVE-2024-451639.1
Mirai botnet C&C uncontrolled resource consumption (kill-switch). NVD
CVE-2024-44809High
Remote code execution affecting embedded / Raspberry Pi targets. NVD
CVE-2024-44808High
Privilege escalation in embedded systems. NVD
CVE-2024-48396Medium
API information disclosure. NVD
CVE-2026-42626Medium
HP printer firmware denial-of-service. NVD
Roblox platformDisclosed
Vulnerability reported and resolved through responsible disclosure.

Plus a high-severity vulnerability disclosed to a Fortune 500 company under NDA. Details withheld by agreement.

In the press

“Researcher Discovers Kill-Switch for Mirai Botnet and Variants.”

CyberInsider, on CVE-2024-45163

Certifications

Offensive-security and compliance certifications behind the practice.

eCPPT eWPT eJPT SSCP CompTIA PenTest+ CompTIA CySA+ CompTIA Security+ CompTIA Network+ CompTIA A+ ITIL 4 Foundation Azure AZ-900

Hire the researcher who broke Mirai.

SOC 2 readiness, penetration testing, AI/LLM security, and fractional CISO leadership, all backed by real published research. See our pricing for these engagements.

Book a strategy call

Frequently asked questions

Who does the security research at traztech?

Our principal, a published security researcher. The research is real, public, and verifiable through assigned CVE identifiers. It is the same hands-on knowledge that goes into client work, which is why our security advice is grounded in how attackers actually operate rather than theory.

What is CVE-2024-45163?

It is a vulnerability discovered by our principal, rated CVSS 9.1 (critical). It functions as a kill-switch for a Mirai botnet variant. It is one of 5 CVEs credited to our principal and is a clear example of the offensive-security depth behind our defensive work.

How many CVEs does the principal have?

5 CVEs, including the CVSS 9.1 finding tracked as CVE-2024-45163. CVEs are publicly assigned identifiers for confirmed vulnerabilities, so this track record is independently verifiable rather than self-reported.

Why does security research matter for your consulting?

Because finding real vulnerabilities forces you to understand systems the way an attacker does. That perspective shapes how we design controls, run assessments, and advise clients. It is the difference between checkbox compliance and security that holds up under actual attack.

Can I work with the researcher directly?

Yes. Our principal leads security engagements directly, including AI/LLM assessments and fractional CISO work. Book a call to discuss your needs. The same person doing the research is the person guiding your security program.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Free templates

Want the practical side of this?

The checklists we actually use on engagements: SOC 2 readiness, ISO 27001 gaps, incident response and vendor security. Free, no card.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.