Neither has tested what happens when someone doesn't follow the rules their tools depend on. I do original research to find out—then help you fix what I find.
When your annual pentest comes back clean, it usually means the testers ran Nessus, checked off compliance boxes, and moved on. It doesn't mean your EDR would catch a sophisticated adversary.
The gap between vendor claims and operational reality is where breaches happen. "Behavioral detection" often means there's a checkbox on the feature list. Validating whether it actually works requires techniques that aren't in the standard playbook.
"I built Veriduct to answer a simple question: what happens when you destroy the format markers that security tools depend on? The answer told me everything about the state of the industry."
Format destruction eliminates file signatures while preserving perfect reconstruction. Same files. Same payloads. Just no patterns for security tools to recognize. Production malware samples went from 143 combined detections to zero—validated on VirusTotal.
That's not a theoretical attack. That's the reality of what your security controls are up against. The question is whether you find out in a controlled engagement or in an incident report.
Test whether your security controls detect threats based on behavior or just signatures. Custom evasion techniques targeting your specific stack—not Metasploit runs—with detailed reporting on what bypassed and why.
Targeted research against your specific security tools. Novel techniques not in public playbooks, delivered as findings plus proof-of-concept. Optionally includes training your team to detect them.
Hands-on workshops teaching techniques that aren't in the standard playbook. Format destruction methodology, behavioral evasion, building detections for novel threats. Your team learns to test—and defend against—these approaches.
Have a specific security question? A control you need validated? A technique you want developed? Scoped engagements built around whatever you actually need to know.
BSidesROC · March 21, 2026 · Rochester, NY
DEF CON DC862 · December 2025 · Parsippany, NJ
15 years building security tools. Recent work: format destruction framework that bypassed 143 detection events. Presented at DEF CON DC862. Available for custom engagements.
I started Bombadil Systems because I kept running into the same gap: security vendors promise behavioral detection, but most controls still rely on signatures and format identification.
The name comes from Tom Bombadil in Tolkien—the one character completely immune to the Ring's power. He operates outside the normal rules. That's the idea: test what happens when attackers don't follow the assumptions your security tools are built on.
Veriduct is open source. The research is public. This isn't about hoarding techniques—it's about helping organizations understand what their controls actually do.
No sales funnel. No marketing calls. Just a direct conversation about what you need to know.
[email protected]