Practitioner-led security research

ThreatCanary Research / Field Notes

Research for the
real attack surface.

Technical analysis of AI runtimes, APIs, identities and exposed systems—grounded in observable behaviour and reproducible evidence.

Original researchEvidence firstAuthorised scope

Latest research

Inside the systems
changing security.

Long-form technical work for security leaders, engineers and practitioners who need to understand the boundary—not just the interface.

AI RUNTIME / SECURITY BOUNDARIES

Exploring the Vulnerabilities of AI: Kicking the Python Sandbox with ChatGPT-5

A practitioner-led examination of the code execution environment behind ChatGPT-5, from shell access and container controls to kernel and network boundaries.

Read the research

Research archive / 001

The article that started the series.

First published in 2024

Research focus

Follow the path.
Validate the impact.

Our work connects isolated technical observations to the systems, identities and business outcomes an attacker can actually reach.

01
AI Security

Test the system, not the promise.

Practical research into agents, model-connected runtimes, prompt boundaries and the infrastructure that turns generated text into action.

Explore AI Offensive Security
02
API Security

Behaviour reveals the real boundary.

Analysis of authorisation, business logic, sensitive data exposure and the API paths that static inventories routinely miss.

Explore API Security
03
Exposure Intelligence

Map what an attacker can chain.

Field notes on external assets, identities, cloud exposure and graph-based validation of realistic attack paths.

Explore Exposure Intelligence

How we work

Proof before opinion.

  1. 01
    Start with a falsifiable hypothesis.

    Define the security boundary and what evidence would prove or disprove it.

  2. 02
    Test within authorised scope.

    Use controlled, reproducible methods that preserve safety and context.

  3. 03
    Publish the path to impact.

    Explain what happened, why it matters and what defenders can do next.

From research to action

Stop counting findings.
Start proving attack paths.

See how ThreatCanary turns exposure intelligence into evidence-backed offensive validation.

Book a technical demo