Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →traztech's founder, Jacob Masse, is a security researcher with six published CVEs and responsible disclosures. One of them, CVE-2024-45163, is a CVSS 9.1 kill-switch for the Mirai botnet that CyberInsider wrote up. That is the offensive-security depth behind every engagement we run.
Mirai is one of the most destructive IoT botnets ever built, the engine behind record-breaking DDoS attacks. Our founder found an unauthenticated flaw (CWE-400) in how Mirai's command-and-control server handles simultaneous TCP connections. A single attacker can exhaust the C&C's resources and take its control infrastructure offline, with no authentication needed. It gives security teams and law enforcement a real way to disrupt active Mirai operations, and CyberInsider ran a full feature on it.
Plus a high-severity vulnerability disclosed to a Fortune 500 company under NDA. Details withheld by agreement.
“Researcher Discovers Kill-Switch for Mirai Botnet and Variants.”
CyberInsider, on CVE-2024-45163Offensive-security and compliance certifications behind the practice.
SOC 2 readiness, penetration testing, AI/LLM security, and fractional CISO leadership, all backed by real published research. See our pricing for these engagements.
Book a strategy callOur founder, a published security researcher. The research is real, public, and verifiable through assigned CVE identifiers. It is the same hands-on knowledge that goes into client work, which is why our security advice is grounded in how attackers actually operate rather than theory.
It is a vulnerability discovered by our founder, rated CVSS 9.1 (critical). It functions as a kill-switch for a Mirai botnet variant. It is one of 6 CVEs credited to our founder and is a clear example of the offensive-security depth behind our defensive work.
6 CVEs, including the CVSS 9.1 finding tracked as CVE-2024-45163. CVEs are publicly assigned identifiers for confirmed vulnerabilities, so this track record is independently verifiable rather than self-reported.
Because finding real vulnerabilities forces you to understand systems the way an attacker does. That perspective shapes how we design controls, run assessments, and advise clients. It is the difference between checkbox compliance and security that holds up under actual attack.
Yes. Our founder leads security engagements directly, including AI/LLM assessments and fractional CISO work. Book a call to discuss your needs. The same person doing the research is the person guiding your security program.