Capability
Zero-day vulnerability research that runs on its own.
XOR-1, the research agent from Vorthix Sec, hunts for vulnerabilities nobody has reported yet. It has produced published CVEs in libexpat, pymonocypher, FreeRDP, and LibRaw, each disclosed in coordination with the upstream maintainers. An engagement applies the same method to the software you ship.
- Published CVEs
- 4+
- Disclosure
- Coordinated with maintainers
- Focus
- Core and open-source infrastructure
The problem
The unknown bugs are the costly ones.
A vulnerability that is not yet public has no signature, no rule, and no patch. It sits in code that passed review and stays there until a researcher, or an attacker, finds it first.
Human researchers can look at one codebase at a time. Hunting continuously across a portfolio takes more hours than most teams can fund.
How XOR-1 works on this
From first hypothesis to a verified report.
- 01
Choose the targets
Start where one flaw has the widest effect: parsers, cryptographic libraries, protocol implementations, and core services.
- 02
Hunt autonomously
XOR-1 reasons about each component, forms hypotheses about its weak points, and pursues them without human guidance.
- 03
Demonstrate the finding
The agent writes the PoC, runs it dynamically, and keeps only what reproduces.
- 04
Disclose responsibly
The research team verifies the result and coordinates the report with the owners before anything is made public.
What your team receives
A handoff engineers can act on.
- Confirmed, previously unknown vulnerabilities
- A working PoC and runtime trace for each one
- Root-cause analysis written for the people who will fix it
- Support with coordinated disclosure
- Verification by the Vorthix research team before delivery
Published work
Findings you can read in full.
Questions
Common questions.
What counts as a zero-day finding?
A vulnerability that has not been publicly reported or patched when XOR-1 finds it. Our published advisories document how each one was found and disclosed.
Are findings disclosed publicly?
Findings go to the maintainers or owners first. Public write-ups follow coordinated release, and anything from a client engagement stays private to that client.
Can XOR-1 research closed-source software?
XOR-1 analyzes compiled binaries as well as source code. Scope and permissions are confirmed with you before any work on proprietary targets.
Does XOR-1 find every vulnerability?
No security process does. XOR-1 reports what it can demonstrate, so the absence of a finding is not proof that no bugs remain.
Keep exploring
More from Vorthix Sec.
Bring us the code that matters most.
Tell us about your software and we will scope the right engagement.