Vulnerability Research
Alongside running pentests, the Tozetta team conducts ongoing in-house research into new vulnerabilities, attack techniques and technologies. We apply this knowledge daily in every pentest, so organizations can count on high-quality, in-depth security research.
Where many parties limit themselves to known scan checklists, our team keeps looking for what could be exploited tomorrow.
- Ongoing in-house research into new vulnerabilities
- Knowledge applied directly in every pentest
- Responsibly reported through responsible disclosure

[ 01 ]Why vulnerability research?
Why vulnerability research?
A pentest relies on the knowledge of the ethical hacker who carries it out. By structurally researching new vulnerabilities and attack techniques ourselves, we ensure that knowledge stays current and doesn't stop at the last training certificate.
Staying ahead of attackers
Cybercriminals and specialized research firms invest continuously in finding new vulnerabilities and attack techniques. By doing our own research, our team stays on top of the latest developments in offensive security.
Directly applicable in pentests
Research that sits in a drawer has no value. We apply insights from our research daily during pentests, so organizations benefit from the most current knowledge and techniques, not outdated scan checklists.
Responsibly reported
Vulnerabilities we come across in third-party software are reported to the relevant vendor through responsible disclosure, so they can be fixed before they are widely exploited.
Certifications
Our ethical hackers are broadly certified
From OffSec to Hack The Box: the Tozetta team sets the bar high with internationally recognized, hands-on certifications. We put that in-depth expertise to work in every pentest, so organizations can count on thorough, high-quality security research.

OSCP
Offensive Security Certified Professional

OSWE
Offensive Security Web Expert

OSEP
Offensive Security Experienced Penetration Tester

OSED
Offensive Security Exploit Developer

OSCE3
Offensive Security Certified Expert 3

CPTS
HTB Certified Penetration Testing Specialist

CWEE
HTB Certified Web Exploitation Expert

CWES
HTB Certified Web Exploitation Specialist

AED
Android Exploit Developer

APIsec
API Penetration Testing

eWPT
Web Application Penetration Tester

BED
Browser Exploit Design

Corelan
Windows Expert-Level Stack Exploit Dev

OSCP
Offensive Security Certified Professional

OSWE
Offensive Security Web Expert

OSEP
Offensive Security Experienced Penetration Tester

OSED
Offensive Security Exploit Developer

OSCE3
Offensive Security Certified Expert 3

CPTS
HTB Certified Penetration Testing Specialist

CWEE
HTB Certified Web Exploitation Expert

CWES
HTB Certified Web Exploitation Specialist

AED
Android Exploit Developer

APIsec
API Penetration Testing

eWPT
Web Application Penetration Tester

BED
Browser Exploit Design

Corelan
Windows Expert-Level Stack Exploit Dev

βEvery vulnerability we discover through our own research becomes a technique that's then built into our pentests as standard. That way our services keep pace with how attackers actually operate.β





[ 02 ]Research areas
Our research areas
Just as specialized parties worldwide categorize vulnerabilities by platform and impact, our research focuses on the domains where our clients actually face risk.
Web applications & APIs
From authentication and authorization logic to modern API architectures: we research how new frameworks and integration patterns can be abused.
Mobile applications
Research into vulnerabilities in native and hybrid apps, from insecure data storage to manipulable communication between app and backend.
Corporate networks & internal systems
Exploration of misconfigurations, lateral movement techniques and privilege escalation paths within corporate networks and Active Directory environments.
AI systems & LLM applications
A relatively new domain where we actively conduct research: prompt injection, model and data leaks, and abuse of AI-driven functionality.
[ 03 ]Our process
From research to responsible disclosure
Vulnerability research at Tozetta isn't a standalone project, but an ongoing process directly connected to our pentesting services.
1. Exploratory research
Our team selects technologies, components or attack techniques relevant to our clients and dives into them, independent of a specific engagement.
2. In-depth analysis & PoC development
Potential vulnerabilities are researched further and, where possible, substantiated with a working proof-of-concept, so the actual impact is established.
3. Internal validation & knowledge sharing
Findings are reviewed within the team and translated into concrete techniques and checks that can be used directly within our pentest methodology.
4. Applied in pentests
From that point on we apply the knowledge gained during every pentest, so clients benefit from the latest insights from our research.
5. Responsible disclosure
We report vulnerabilities found in third-party software to the relevant vendor in a controlled manner, giving them enough time to fix the issue before details become more widely known.
βWe are very satisfied with Tozetta's services and highly recommend them to companies looking for professional cybersecurity support. Their dedication, expertise, and great collaboration have had a positive impact on the security of our software.β
βAs a business service provider, Risk Solutions Caribbean conducts objective and independent investigations into wrongdoing within organizations. We also support organizations with their legally required compliance tasks. Tozetta supports us in the cybersecurity domain.β
βWe deliberately chose Tozetta for the combination of technical depth, pragmatic advice, and reliability. The reports are clear and immediately actionable, so findings don't sit on a shelf but actually get addressed.β
βSecurity is a key focus for us. We have an experienced development team that works on software development and security issues every day. At the same time, we wanted to deepen our knowledge further and have our approach critically reviewed by external experts. Tozetta's technical security awareness training really moved our team forward.β
βIn our network, we know several parties that provide pentesting services. We had an introductory conversation with these parties, and Tozetta came out on top. Their practical approach and short lines of communication were decisive for us.β
βAn annual pentest is only a snapshot in time. Now I can show at any moment whether and which vulnerabilities exist, and act on them. Every version we release is automatically tested for known vulnerabilities by the Continuous Technical Vulnerability Scanner. That gives me the feeling that we're in control, and it makes us stronger against cyber threats.β
βI have to say the report was really excellent. Clear, reproducible, and therefore usable. I was extremely pleasantly surprised. Thatβs why we highly recommend Tozetta!β
βAs a large membership platform, we take cybersecurity extremely seriously. That's why we chose to have a pentest carried out. SeniorWeb is very happy with Tozetta's service: communication was clear and effective, and everything was ultimately documented in a professional report.β
βWe are very satisfied with Tozetta's services and highly recommend them to companies looking for professional cybersecurity support. Their dedication, expertise, and great collaboration have had a positive impact on the security of our software.β
βAs a business service provider, Risk Solutions Caribbean conducts objective and independent investigations into wrongdoing within organizations. We also support organizations with their legally required compliance tasks. Tozetta supports us in the cybersecurity domain.β
βWe deliberately chose Tozetta for the combination of technical depth, pragmatic advice, and reliability. The reports are clear and immediately actionable, so findings don't sit on a shelf but actually get addressed.β
βSecurity is a key focus for us. We have an experienced development team that works on software development and security issues every day. At the same time, we wanted to deepen our knowledge further and have our approach critically reviewed by external experts. Tozetta's technical security awareness training really moved our team forward.β
βIn our network, we know several parties that provide pentesting services. We had an introductory conversation with these parties, and Tozetta came out on top. Their practical approach and short lines of communication were decisive for us.β
βAn annual pentest is only a snapshot in time. Now I can show at any moment whether and which vulnerabilities exist, and act on them. Every version we release is automatically tested for known vulnerabilities by the Continuous Technical Vulnerability Scanner. That gives me the feeling that we're in control, and it makes us stronger against cyber threats.β
βI have to say the report was really excellent. Clear, reproducible, and therefore usable. I was extremely pleasantly surprised. Thatβs why we highly recommend Tozetta!β
βAs a large membership platform, we take cybersecurity extremely seriously. That's why we chose to have a pentest carried out. SeniorWeb is very happy with Tozetta's service: communication was clear and effective, and everything was ultimately documented in a professional report.β
[ 04 ]Target audience
Who is this for?

Our research background is woven directly into every pentest we carry out, from web application to AI system.
Organizations that want to know their pentest partner does more than work through existing scan checklists
Companies with critical or complex systems, where deep, tailored research adds real value
Organizations using AI systems and LLM applications who want to know how these can be abused
Anyone curious about the expertise behind a Tozetta pentest
Partners
In cybersecurity, you work together:
































































































































Frequently asked questions about vulnerability research
What is vulnerability research?
How does this differ from a regular pentest?
What do you do with vulnerabilities you find?
What areas do you research?
Do you sell vulnerabilities or exploits, like in exploit-acquisition programs?
Can I benefit from your research as a client without purchasing a pentest?
Curious about our expertise?
Get in touch without obligation or schedule an introduction directly.