Praetorian
Praetorian is an offensive security company dedicated to finding critical vulnerabilities before attackers do. From hands-on adversarial testing to the Guard, our AI-powered platform that continuously finds and prioritizes the exposures that matter most, we turn offensive security into a lasting advantage. The Guard is backed by the top 2% of offensive security operators worldwide.
Can an AI write a working kernel exploit? In Part 2 of our FreeBSoD research, we had Claude build two chains that fully escape a FreeBSD VNET jail and run code on the host.
Chain 1: stack overflow + info leak to beat stack canaries and KASLR.
Chain 2: malloc-32768 heap groom + pipe-file type confusion to disable SMEP/SMAP via one fchown syscall.
What the model handled, where it needed a human 👇
https://www.praetorian.com/blog/llm-kernel-exploit-development/
Can an AI write a working kernel exploit? In Part 2 of FreeBSoD, we had Claude build two chains that fully escape a FreeBSD VNET jail and run code on the host.
Chain 1: stack overflow + info leak to beat stack canaries and KASLR.
Chain 2: malloc-32768 heap groom + pipe-file type confusion to disable SMEP/SMAP via one fchown syscall.
What the model handled, where it needed a human 👇
https://www.praetorian.com/blog/llm-kernel-exploit-development/
#infosec #FreeBSD #OffensiveSecurity #Praetorian #PraetorianGuard
Happy 4th of July from the team at Praetorian! 🇺🇸
Bridging the GAP at DEF CON Training Las Vegas 2026. Hands-on embedded hardware hacking, take-home kit included.
Code DCTLV26-250-select for $250 off.
WasmForge is open source today. ⚒️ It compiles GhostPack C# tools like Rubeus and Seatbelt to WebAssembly and runs them outside the .NET runtime, out of reach of AMSI and ETW. Full pipeline, Apache 2.0.
https://www.praetorian.com/blog/wasmforge-csharp-ghostpack-edr-evasion/
Praetorian's Adam Crosser pointed Claude Code at the FreeBSD kernel and found eight zero-days in days, including CVE-2026-3038, an RTSock stack overflow patched a day after we reported it.
Part one is the methodology: CodeQL and semgrep triage, a KASAN feedback loop for verification, and keeping the whole thing on a $100 plan.
https://www.praetorian.com/blog/ai-vulnerability-research-freebsd-kernel/
Praetorian Guard now runs fully autonomous, persistent attacks.
Meet Hannibal. Define a directive and it continuously tasks the compute fleet against your targets. It runs iteratively, learns across runs, and files risks on demonstrated compromise.
"Hannibal ad portas."
Sulla: our open source SMB secret scanner for finding credentials exposed across network shares.
Runs from any Linux box. Auto-discovers readable shares, scans with Titus, surfaces high-signal findings. Quick mode sweeps ~10,000 computer objects in as fast as 30 min.
🔗 Full Write Up: https://www.praetorian.com/blog/sharing-is-caring-smb-secret-scanning-with-sulla/
🔗 Open Source: https://github.com/praetorian-inc/Sulla
DEF CON Training 2026. Aug 10-11. Come hack with us.
Meet Unit-01, our Praetorian.
Continuous, autonomous offensive security modeled on history’s ultimate insiders. Unit-01 doesn't wait for annual pentests; he continuously maps every path into your environment just like a real attacker, reporting to you first.
The missing face is intentional. It means zero assumptions about how your system is "supposed" to work. He only sees what an attacker sees: doors, and which ones are unlocked.
Please welcome:
Taggart Solomon joins as Offensive Security Manager after 5 years with the U.S. Army, NSA, and USCYBERCOM.
Indivara Kolluru is a summer intern on our offsec lab team. A rising sophomore at Carnegie Mellon, he researches how AI systems fail before attackers figure it out.
Meet Brutus, our open-source credential testing tool. Now look closely. 🗝️
A number on a gravestone. A date carved in the floor. A pun you'll groan at. We hid details only someone who's lived in a terminal would catch.
How many can you find? 👇
Free on GitHub: github.com/praetorian-inc/brutus
Full Write Up: https://www.praetorian.com/blog/et-tu-default-creds-introducing-brutus-for-modern-credential-testing/
#CredentialSecurity #PenTesting #OffensiveSecurity #Praetorian #PraetorianGuard
Centurion is our x86-64-inspired VM that runs a freestanding userland environment behind an interpretation layer to bypass EDR memory scanners. mbedTLS and coreHTTP run as bytecode in an 18 KB native stub, with a software crypto coprocessor dispatching bignum kernels natively. We built it in a week using GCC/LLVM test suites as an agent feedback loop. Writeup by Adam Crosser:
https://www.praetorian.com/blog/virtualized-loader-centurion/
Default, weak, and leaked credentials are the traitor already sitting inside your most defended systems. Every fortified gate trusts a familiar face.
Brutus is our open-source credential testing tool: default, weak, and leaked validation across 20+ protocols. 🗝️
https://github.com/praetorian-inc/brutus
https://www.praetorian.com/blog/et-tu-default-creds-introducing-brutus-for-modern-credential-testing/
#CredentialSecurity #PenTesting #OffensiveSecurity #Praetorian #PraetorianGuard
Meet Augustus, our open-source LLM jailbreak testing harness. Now look closely. 🏛️
The pillars aren't decoration. The scroll has a version number. The Oracle is guarding something specific. We hid a pile of details only someone who's tested an LLM would catch.
How many can you spot? 👇
https://github.com/praetorian-inc/augustus
#LLMSecurity #RedTeam #OffensiveSecurity #Praetorian #PraetorianGuard
86% of production LLMs are vulnerable to prompt injection, and the successful attacks are almost never direct. They're multi-turn: rapport, indirection, a callback, then the breach.
Augustus is our open-source harness for multi-turn LLM jailbreak testing: 210+ probes, 4 attack strategies, 28 providers. 🏛️
https://github.com/praetorian-inc/augustus
#LLMSecurity #RedTeam #OffensiveSecurity #Praetorian #PraetorianGuard
Meet Aurelian, our open-source multi-cloud recon tool. Now look closely. ☁️
Three banners. Three gravestones. One very deliberate color palette. We hid details only a cloud security engineer would catch.
How many can you spot? 👇
https://github.com/praetorian-inc/aurelian
#CloudSecurity #MultiCloud #OffensiveSecurity #Praetorian #PraetorianGuard