Is vulnerability research a fit for your business?

Vulnerability Research

Alongside running pentests, the Tozetta team conducts ongoing in-house research into new vulnerabilities, attack techniques and technologies. We apply this knowledge daily in every pentest, so organizations can count on high-quality, in-depth security research.

Where many parties limit themselves to known scan checklists, our team keeps looking for what could be exploited tomorrow.

  • Ongoing in-house research into new vulnerabilities
  • Knowledge applied directly in every pentest
  • Responsibly reported through responsible disclosure
Tozetta ethical hacker during vulnerability research

[ 01 ]Why vulnerability research?

Why vulnerability research?

A pentest relies on the knowledge of the ethical hacker who carries it out. By structurally researching new vulnerabilities and attack techniques ourselves, we ensure that knowledge stays current and doesn't stop at the last training certificate.

01

Staying ahead of attackers

Cybercriminals and specialized research firms invest continuously in finding new vulnerabilities and attack techniques. By doing our own research, our team stays on top of the latest developments in offensive security.

02

Directly applicable in pentests

Research that sits in a drawer has no value. We apply insights from our research daily during pentests, so organizations benefit from the most current knowledge and techniques, not outdated scan checklists.

03

Responsibly reported

Vulnerabilities we come across in third-party software are reported to the relevant vendor through responsible disclosure, so they can be fixed before they are widely exploited.

Certifications

Our ethical hackers are broadly certified

From OffSec to Hack The Box: the Tozetta team sets the bar high with internationally recognized, hands-on certifications. We put that in-depth expertise to work in every pentest, so organizations can count on thorough, high-quality security research.

OSCP

OSCP

Offensive Security Certified Professional

OSWE

OSWE

Offensive Security Web Expert

OSEP

OSEP

Offensive Security Experienced Penetration Tester

OSED

OSED

Offensive Security Exploit Developer

OSCE3

OSCE3

Offensive Security Certified Expert 3

CPTS

CPTS

HTB Certified Penetration Testing Specialist

CWEE

CWEE

HTB Certified Web Exploitation Expert

CWES

CWES

HTB Certified Web Exploitation Specialist

AED

AED

Android Exploit Developer

APIsec

APIsec

API Penetration Testing

eWPT

eWPT

Web Application Penetration Tester

BED

BED

Browser Exploit Design

Corelan

Corelan

Windows Expert-Level Stack Exploit Dev

OSCP

OSCP

Offensive Security Certified Professional

OSWE

OSWE

Offensive Security Web Expert

OSEP

OSEP

Offensive Security Experienced Penetration Tester

OSED

OSED

Offensive Security Exploit Developer

OSCE3

OSCE3

Offensive Security Certified Expert 3

CPTS

CPTS

HTB Certified Penetration Testing Specialist

CWEE

CWEE

HTB Certified Web Exploitation Expert

CWES

CWES

HTB Certified Web Exploitation Specialist

AED

AED

Android Exploit Developer

APIsec

APIsec

API Penetration Testing

eWPT

eWPT

Web Application Penetration Tester

BED

BED

Browser Exploit Design

Corelan

Corelan

Windows Expert-Level Stack Exploit Dev

Ian van der Wurff, ethical hacker

β€œEvery vulnerability we discover through our own research becomes a technique that's then built into our pentests as standard. That way our services keep pace with how attackers actually operate.”

Ian van der Wurff

Ethical Hacking Lead, Tozetta

OSCP
OSED
OSWE
OSEP
OSCE3

[ 02 ]Research areas

Our research areas

Just as specialized parties worldwide categorize vulnerabilities by platform and impact, our research focuses on the domains where our clients actually face risk.

Web applications & APIs

From authentication and authorization logic to modern API architectures: we research how new frameworks and integration patterns can be abused.

Mobile applications

Research into vulnerabilities in native and hybrid apps, from insecure data storage to manipulable communication between app and backend.

Corporate networks & internal systems

Exploration of misconfigurations, lateral movement techniques and privilege escalation paths within corporate networks and Active Directory environments.

AI systems & LLM applications

A relatively new domain where we actively conduct research: prompt injection, model and data leaks, and abuse of AI-driven functionality.

[ 03 ]Our process

From research to responsible disclosure

Vulnerability research at Tozetta isn't a standalone project, but an ongoing process directly connected to our pentesting services.

1

1. Exploratory research

Our team selects technologies, components or attack techniques relevant to our clients and dives into them, independent of a specific engagement.

2

2. In-depth analysis & PoC development

Potential vulnerabilities are researched further and, where possible, substantiated with a working proof-of-concept, so the actual impact is established.

3

3. Internal validation & knowledge sharing

Findings are reviewed within the team and translated into concrete techniques and checks that can be used directly within our pentest methodology.

4

4. Applied in pentests

From that point on we apply the knowledge gained during every pentest, so clients benefit from the latest insights from our research.

5

5. Responsible disclosure

We report vulnerabilities found in third-party software to the relevant vendor in a controlled manner, giving them enough time to fix the issue before details become more widely known.

β€œWe are very satisfied with Tozetta's services and highly recommend them to companies looking for professional cybersecurity support. Their dedication, expertise, and great collaboration have had a positive impact on the security of our software.”

Infowijs

Patrick van Marsbergen

Tech Lead, Infowijs

β€œAs a business service provider, Risk Solutions Caribbean conducts objective and independent investigations into wrongdoing within organizations. We also support organizations with their legally required compliance tasks. Tozetta supports us in the cybersecurity domain.”

Risk Solutions Caribbean

Ruud Hamers

Managing Director, Risk Solutions Caribbean

β€œWe deliberately chose Tozetta for the combination of technical depth, pragmatic advice, and reliability. The reports are clear and immediately actionable, so findings don't sit on a shelf but actually get addressed.”

ACE

ACE

β€œSecurity is a key focus for us. We have an experienced development team that works on software development and security issues every day. At the same time, we wanted to deepen our knowledge further and have our approach critically reviewed by external experts. Tozetta's technical security awareness training really moved our team forward.”

POM

POM

β€œIn our network, we know several parties that provide pentesting services. We had an introductory conversation with these parties, and Tozetta came out on top. Their practical approach and short lines of communication were decisive for us.”

SVC Groep

SVC Groep

β€œAn annual pentest is only a snapshot in time. Now I can show at any moment whether and which vulnerabilities exist, and act on them. Every version we release is automatically tested for known vulnerabilities by the Continuous Technical Vulnerability Scanner. That gives me the feeling that we're in control, and it makes us stronger against cyber threats.”

McMain Software

McMain Software

β€œI have to say the report was really excellent. Clear, reproducible, and therefore usable. I was extremely pleasantly surprised. That’s why we highly recommend Tozetta!”

SensingClues

SensingClues

β€œAs a large membership platform, we take cybersecurity extremely seriously. That's why we chose to have a pentest carried out. SeniorWeb is very happy with Tozetta's service: communication was clear and effective, and everything was ultimately documented in a professional report.”

SeniorWeb

SeniorWeb

β€œWe are very satisfied with Tozetta's services and highly recommend them to companies looking for professional cybersecurity support. Their dedication, expertise, and great collaboration have had a positive impact on the security of our software.”

Infowijs

Patrick van Marsbergen

Tech Lead, Infowijs

β€œAs a business service provider, Risk Solutions Caribbean conducts objective and independent investigations into wrongdoing within organizations. We also support organizations with their legally required compliance tasks. Tozetta supports us in the cybersecurity domain.”

Risk Solutions Caribbean

Ruud Hamers

Managing Director, Risk Solutions Caribbean

β€œWe deliberately chose Tozetta for the combination of technical depth, pragmatic advice, and reliability. The reports are clear and immediately actionable, so findings don't sit on a shelf but actually get addressed.”

ACE

ACE

β€œSecurity is a key focus for us. We have an experienced development team that works on software development and security issues every day. At the same time, we wanted to deepen our knowledge further and have our approach critically reviewed by external experts. Tozetta's technical security awareness training really moved our team forward.”

POM

POM

β€œIn our network, we know several parties that provide pentesting services. We had an introductory conversation with these parties, and Tozetta came out on top. Their practical approach and short lines of communication were decisive for us.”

SVC Groep

SVC Groep

β€œAn annual pentest is only a snapshot in time. Now I can show at any moment whether and which vulnerabilities exist, and act on them. Every version we release is automatically tested for known vulnerabilities by the Continuous Technical Vulnerability Scanner. That gives me the feeling that we're in control, and it makes us stronger against cyber threats.”

McMain Software

McMain Software

β€œI have to say the report was really excellent. Clear, reproducible, and therefore usable. I was extremely pleasantly surprised. That’s why we highly recommend Tozetta!”

SensingClues

SensingClues

β€œAs a large membership platform, we take cybersecurity extremely seriously. That's why we chose to have a pentest carried out. SeniorWeb is very happy with Tozetta's service: communication was clear and effective, and everything was ultimately documented in a professional report.”

SeniorWeb

SeniorWeb

[ 04 ]Target audience

Who is this for?

Tozetta team during vulnerability research

Our research background is woven directly into every pentest we carry out, from web application to AI system.

Organizations that want to know their pentest partner does more than work through existing scan checklists

Companies with critical or complex systems, where deep, tailored research adds real value

Organizations using AI systems and LLM applications who want to know how these can be abused

Anyone curious about the expertise behind a Tozetta pentest

Partners

In cybersecurity, you work together:

AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer
AVG Compleet
OpenSight
Risk Solutions Caribbean
HOB ICT Security
Pronidus
International Security Partners
Innvolve
CyberSafer

Frequently asked questions about vulnerability research

What is vulnerability research?
Vulnerability research is the in-depth investigation of software, systems and technologies for as-yet-unknown vulnerabilities and attack techniques. It goes beyond testing one specific application: it's fundamental research into how systems can be abused.
How does this differ from a regular pentest?
A pentest tests a specific application or environment at a fixed point in time within an agreed scope. Vulnerability research is ongoing, exploratory research that generates new knowledge and techniques. We then apply that knowledge daily in every pentest we carry out.
What do you do with vulnerabilities you find?
Vulnerabilities we come across in third-party software are reported to the relevant vendor through responsible disclosure, so they can be fixed before they are widely exploited. Research directly related to a client is of course shared directly and confidentially with that client.
What areas do you research?
Our team researches a wide range of domains, including web applications and APIs, mobile applications, corporate networks and internal systems, and (more recently) AI systems and LLM applications.
Do you sell vulnerabilities or exploits, like in exploit-acquisition programs?
No. Specialized programs exist worldwide that pay handsomely for working zero-day exploits, which shows how much value is placed on high-quality vulnerability research. Tozetta deliberately chooses a different path: we use our knowledge to protect clients, and we responsibly report vulnerabilities in third-party software to the vendor, rather than selling them.
Can I benefit from your research as a client without purchasing a pentest?
Our expertise is most visible in the depth of our pentests, where we apply this knowledge directly. Feel free to get in touch to discuss how our research background connects to your specific question.

Curious about our expertise?

Get in touch without obligation or schedule an introduction directly.