Zain Dana Harperauthorized offensive security

Adversarial capability, under authorization.

A private line, held apart from the open tools. Offensive and dual-use security capability, built for lawful operators and shared only after authorization is established. It sits where the accountable engineering here meets work that demands encryption, authorization, and oversight.

Nothing on this page is offered for unauthorized use. A request without a lawful basis is not answered.

private line · in active development · shared under lawful authorization · qualified contact only

Authorization comes first.

Developed privately, shared only under law. Offensive and dual-use capability goes to lawfully authorized parties only: accredited law-enforcement bodies, government agencies, and organizations testing their own infrastructure. It is disclosed after the requesting entity establishes the legal authority to receive it, not before.

The lawful basis precedes the work. It is not paperwork filed after the fact.

Where a lawful basis cannot be established, the work is not shared, for any party or any price. That constraint is the point of the practice, not an obstacle to route around.

Who this is for.

Law enforcement and government Coordinated, lawful operations, and action against cybercriminals. Capability is provided to accredited bodies, under their authorization and oversight.
AI organizations Explicit adversarial tooling to test AI systems on your own infrastructure, under your authorization. Its own section, below.
No one else Capability is not sold, shared, or demonstrated to unauthorized parties. There is no consumer edition and no open download.

For AI labs: a real adversary, on your own infrastructure.

The AI tooling stresses a system the way a real attacker would, not the way a checklist does. It runs inside your environment, under your authorization, so nothing leaves your control and no live capability passes to a third party. It is built for red-team and assurance programs that need pressure stronger than a public benchmark, against models, agents, and the tools they reach.

The areas below map to how these systems fail. Named at domain level; tooling and methods are shared only under authorization. on your infrastructure · under your authorization

Prompt injection and jailbreak how far instructions and guardrails hold under adversarial and indirect input
Model extraction and inversion what an attacker can reconstruct of the model, its prompts, or its data
Agent and tool abuse the privilege, scope, and tool-use paths an autonomous system can be driven down
Training-data and supply-chain integrity poisoning, provenance, and the trust chain that runs into the weights
Data exfiltration paths that move sensitive context, secrets, or user data out of the system
Guardrail and refusal stress where safety behavior holds under pressure and where it bends

Capability index, redacted.

These areas are named at domain level. Tooling, techniques, and operational detail are disclosed only to authorized parties, under agreement. This is a map of the practice, not a catalog of methods, and it is deliberately incomplete.

Adversary emulation full-scope emulation of real threat actors, scoped to the authorized operation details under authorization
Malware analysis and attribution understanding hostile tooling and tracing it toward source, in support of lawful action details under authorization
Operational tooling capability built to the authorized requirement and delivered under agreement, not enumerated here details under authorization
Secure communications encryption, key management, and operational security for sensitive engagements details under authorization
Custom development purpose-built to the mission and disclosed only to the authorized party details under authorization

How an engagement works.

  1. 01Establish authorization. The lawful basis and the authority to receive the work are agreed before anything is shared.
  2. 02Scope, in writing. What is in bounds, what is not, and who oversees it.
  3. 03Deliver under oversight. Work proceeds inside the agreed scope, with a record of what was done.
  4. 04Nothing outside scope. No capability is retained, reused, or repurposed beyond the authorized engagement.

Contact.

Qualified inquiries establish contact through the About page and state the authority and the lawful basis for the request. A request without one is not answered.

Authorized parties only. This page names a practice; it does not distribute capability.