Your EDR vendor promises behavioral detection.
Your pentest firm says all clear.

Neither has tested what happens when someone doesn't follow the rules their tools depend on. I do original research to find out—then help you fix what I find.

See the research
Veriduct Research

Production malware—Cobalt Strike, Emotet, ValleyRAT—went from 143 combined detections to zero.

98%
Analytical capability loss in blint testing. Security tools couldn't identify what they were looking at.
Format destruction
100%
Perfect reconstruction verified by SHA256. Not corruption—systematic reversable transformation.
Validated methodology

When your annual pentest comes back clean, it usually means the testers ran Nessus, checked off compliance boxes, and moved on. It doesn't mean your EDR would catch a sophisticated adversary.

The gap between vendor claims and operational reality is where breaches happen. "Behavioral detection" often means there's a checkbox on the feature list. Validating whether it actually works requires techniques that aren't in the standard playbook.

"I built Veriduct to answer a simple question: what happens when you destroy the format markers that security tools depend on? The answer told me everything about the state of the industry."

Format destruction eliminates file signatures while preserving perfect reconstruction. Same files. Same payloads. Just no patterns for security tools to recognize. Production malware samples went from 143 combined detections to zero—validated on VirusTotal.

That's not a theoretical attack. That's the reality of what your security controls are up against. The question is whether you find out in a controlled engagement or in an incident report.

Engagements

01

Red Team Assessment

Test whether your security controls detect threats based on behavior or just signatures. Custom evasion techniques targeting your specific stack—not Metasploit runs—with detailed reporting on what bypassed and why.

Includes: Detection capability testing, behavioral analysis gaps, remediation roadmap
02

Evasion Research

Targeted research against your specific security tools. Novel techniques not in public playbooks, delivered as findings plus proof-of-concept. Optionally includes training your team to detect them.

Includes: EDR/DLP bypass research, custom technique development, detection guidance
03

Advanced Training

Hands-on workshops teaching techniques that aren't in the standard playbook. Format destruction methodology, behavioral evasion, building detections for novel threats. Your team learns to test—and defend against—these approaches.

Includes: Workshop materials, lab exercises, methodology documentation
04

Custom Research

Have a specific security question? A control you need validated? A technique you want developed? Scoped engagements built around whatever you actually need to know.

Includes: Scoping call, custom research, deliverables tailored to your question
Validated on VirusTotal
Tested on ANY.RUN
DEF CON DC862 presentation
About

Chris Aziz

Founder, Bombadil Systems
Upcoming talk

Testing Security Controls: Do They Detect Behavior or Just File Signatures?

BSidesROC · March 21, 2026 · Rochester, NY

Recent talk

Format Destruction for Security Testing

DEF CON DC862 · December 2025 · Parsippany, NJ

15 years building security tools. Recent work: format destruction framework that bypassed 143 detection events. Presented at DEF CON DC862. Available for custom engagements.

I started Bombadil Systems because I kept running into the same gap: security vendors promise behavioral detection, but most controls still rely on signatures and format identification.

The name comes from Tom Bombadil in Tolkien—the one character completely immune to the Ring's power. He operates outside the normal rules. That's the idea: test what happens when attackers don't follow the assumptions your security tools are built on.

Veriduct is open source. The research is public. This isn't about hoarding techniques—it's about helping organizations understand what their controls actually do.

Ready to find out what your controls actually do?

No sales funnel. No marketing calls. Just a direct conversation about what you need to know.

[email protected]
I read everything and respond personally.