We only do this
No web apps, no compliance checklists. Kernel and native C++ is the entire business, so the hard part of your engagement isn't the part we subcontract.
TraceFault is a specialist practice for Windows kernel drivers and native C++ applications — the software where a single missed check hands over the whole machine.
Remote engagements · NDA before scope · Reply within two business days
No web apps, no compliance checklists. Kernel and native C++ is the entire business, so the hard part of your engagement isn't the part we subcontract.
Every finding is demonstrated on your build with working code. You get something your engineers can run, not a severity rating and a shrug.
A retest round is included in the fee. We review the patch itself, not just whether the original proof-of-concept stopped working.
Four ways in, depending on where your software is and what's keeping you up at night.
A full attack-surface review of your WDM or KMDF driver, from the dispatch routines down. We assume the caller is hostile, unprivileged and patient.
Source-assisted review of native applications — memory safety, trust boundaries and the parsers that quietly accept whatever they're given.
You have a crash and a deadline. We tell you whether it's a denial of service or a privilege escalation, and we prove which one it is.
Mitigations, build configuration and privilege boundaries assessed against how attackers actually work today — not against a 2015 checklist.
Binary-only targets are normal work here. Source access widens coverage for the same budget, but it was never the requirement.
Harnesses built around your real entry points, tuned until they find things. You keep everything we build.
Lifetime bugs, allocation arithmetic and the races that only show up under load — the class of flaw that still carries most real-world impact.
Everywhere a low-privileged process can reach something running as SYSTEM, and what it can do once it gets there.
The person who scopes your engagement is the person who does the work. There's no bench of junior testers, no template report with your logo dropped into it, and nothing gets handed off halfway through.
Engagements typically run two to four weeks and are quoted as a fixed fee after scoping. Findings reach you as they're confirmed — anything critical the same day.
NDA, a call, and written authorisation naming the targets. We agree what a finding has to prove before anyone starts.
Manual review alongside targeted fuzzing. Every candidate bug is driven until it either becomes a real primitive or gets ruled out.
A written report, a walkthrough with your engineers, and one retest round once your fixes ship. The retest is included.
Tell us what you've built and what worries you about it. A scoping call costs nothing.
contact@tracefault.dev
We test only systems our clients are authorised to have tested, under written authorisation naming the targets.