What we do

Turbine focuses on low-level security engineering, Windows internals, endpoint detection and response, malware reverse engineering, EDR/sensor development, memory, and instrumentation work.

Our research →
Windows internals & low-level engineering
Native APIs, kernel paths, drivers, and the syscall boundary. Correctness at the byte level, not the framework level.
Vulnerability research
Bug hunting, exploit development, and root cause analysis. Proof of concept is the start, not the finish. The goal is to know exactly why a system fails.
Malware analysis & EDR development
Static and dynamic analysis of real samples, paired with research into how detection and response tooling works under the hood, and where it breaks.
Articles
Technical write-ups on Windows internals, EDRs, vulnerability research, malware analysis, and reverse engineering.
Capability
A closer look at what's being built and the tooling that comes out of the research.

If you're working on something similar, or just want to talk shop, get in touch.

Get in touch GitHub