Red Team Operations

Full-scope offensive adversary simulations, defense evasion, and stealth intrusion campaigns testing real-world organizational resilience.

Insights, proactively delivered

ASF-001: Active Directory Kerberoasting to Domain Admin

[CVSS 9.8 Critical] Extracted Kerberos TGS tickets for SPN-configured service accounts, cracked offline, and pivoted directly to full Domain Compromise.

View Exploit Brief & PoC

GenericAll ACL Misconfiguration Escalation

ASF-005: GenericAll ACL Misconfiguration Escalation

[CVSS 8.8 High] Exploited excessive DACL rights over security groups to force password resets and escalate unprivileged domain accounts to Tier-0.

View Exploit Brief & PoC

ASF-015: Golden Ticket Persistence via KRBTGT

[CVSS 9.9 Critical] Forged Kerberos Ticket Granting Tickets (TGT) utilizing extracted KRBTGT master key hash for undetectable persistent domain dominance.

Get app

Custom analytics reports

AMN Framework compiles executive risk dashboards and technical CVSS reports directly from raw telemetry.

View Exploit Brief & PoC

Zero-Day Path Traversal & Remote Code Execution

Generate theme edits

Tell Sidekick the specific design updates you want and watch it adjust your theme instantly.

View Exploit Brief & PoC

Studio-quality photos

Prompt Sidekick to change image backgrounds, add or remove elements, and expand canvas size.

View Exploit Brief & PoC

Tedious tasks, simplified

Shortcuts for prompts

Turn your Sidekick prompts into reusable Skills, then share your favorites with the community and discover new ones to try.

View Exploit Brief & PoC

Multi-step task completion

Partner with Sidekick on more complex tasks now that it can plan, write to-do lists, and take on multiple actions.

View Exploit Brief & PoC

Wide-mode

Sidekick goes full screen so you can tackle complex tasks with more room to work.

App discovery

Sidekick can help you find, compare, and install apps.

Target selection

Sidekick gives contextual answers when clicking on specific areas of the admin.

Better memory

Sidekick remembers your chats and unique user preferences.

Active Directory Security

Enterprise Identity, Kerberos authentication protocols, DACL/ACE analysis, BloodHound attack path mapping, and Domain Controller hardening.

ASF-008: BloodHound Shortest Path via Unconstrained Delegation

[CVSS 9.0 Critical] Mapped shortest attack path executing TGS extraction against unconstrained delegation server hosting Domain Controller replication sessions.

View Exploit Brief & PoC

ASF-010: NTLM Relay Attack against AD CS Web Enrollment

[CVSS 8.8 High] Relayed machine account NTLM authentications to AD CS web enrollment endpoints, forging valid certificate templates for domain privilege escalation.

Web & API Security

Deep-dive assessments covering OWASP Top 10, GraphQL authorization flaws, BOLA/IDOR, SSRF cloud metadata exposure, and Pre-Auth RCE vulnerabilities.

ASF-002: Pre-Auth RCE in Enterprise ERP Portal

[CVSS 9.8 Critical] Discovered unauthenticated Java deserialization flaw allowing arbitrary command execution with SYSTEM privileges on internal application cluster.

View Exploit Brief & PoC

ASF-004: BOLA / IDOR Financial Transaction Tampering

[CVSS 8.8 High] Broken Object Level Authorization across payment endpoints allowing client-side parameter manipulation to tamper with invoice totals and order settlement amounts.

Get app

ASF-006: Server-Side Request Forgery (SSRF) to Cloud Metadata

[CVSS 9.1 Critical] Exploited webhook asset parser to dispatch authenticated intranet requests, successfully extracting AWS/GCP instance metadata and cloud IAM credentials.

View Exploit Brief & PoC
A Wordpress editor is open and products are being added to the site.

ASF-007: Cross-Tenant Data Leakage via GraphQL API

[CVSS 8.5 High] Insufficient scoping in multi-tenant GraphQL resolvers permitting unauthorized cross-organization querying of confidential customer records and billing data.

View Exploit Brief & PoC

Unlisted product status

Hide products from search results, collections, and more, while keeping them accessible with a direct URL.

Unit pricing for all

Display prices by weight, volume, length, or quantity in metric, imperial, or counts, now available globally.

Vibe code with Lovable

Deploy ephemeral adversary infrastructure in seconds with automated DNS, SSL certificates, and redirectors.

Improved theme discovery

Find a theme with improved search, more precise industry filters, and templates with less manual setup.

Autofill passcode on iOS 26

Credentials can sign into their account without leaving the browser using Apple's iOS 26 passcode autofill.

ASF-014: Remote Code Execution via SSTI in Notification Engine

[CVSS 9.4 Critical] Server-Side Template Injection within email template rendering engine, leading to sandbox escape and interactive shell access as privileged system user.

Get app

Findings Archive

Deep-dive technical archive of high-severity CVEs, zero-days, and complex exploit chains discovered in enterprise production systems.

ASF-009: Blind SQL Injection in Core Billing Engine

[CVSS 8.9 High] Exploited time-based blind SQL injection in ledger calculation endpoint to dump sensitive financial tables, database schemas, and administrative password hashes.

View Finding

ASF-011: Mass Assignment on User Role Provisioning Endpoint

[CVSS 8.2 High] Exploited unvalidated parameter binding in user registration API to elevate standard accounts to organization SuperAdmin status without authorization.

ASF-012: Zero-Day Path Traversal & Arbitrary File Read in VPN Gateway

[CVSS 8.6 High] Unauthenticated path traversal in SSL-VPN appliance web portal allowing direct extraction of system configuration files, private keys, and active user sessions.

View Advisory
  • Compatible with iPad via MFi Authentication Coprocessor
  • Performance powered by ARM Cortex-A7 MPU with built-in data security
  • Built-in health monitoring with automatic fault recovery
  • Automatic firmware updates
  • Rock-solid connectivity with 3 USB-A ports and 1 USB‑C port
A HP barcode scanner with a red light.

ASF-003: AS-REP Roasting & Kerberos Bypass

[CVSS 7.5 High] Identified Active Directory accounts with Kerberos pre-authentication disabled, requested AS-REP tickets, and cracked hashes offline to compromise credentials.

Visit hardware store
On the POS, there is a modal where a subscription is being added for a skate magazine.

ASF-013: DCSync & KRBTGT Hash Extraction

[CVSS 9.3 Critical] Leveraged replication rights via Mimikatz to extract the Active Directory KRBTGT password hash, enabling enterprise-wide domain compromise.

View Exploit Brief & PoC

Quick count with POS

Scan and update inventory directly from your POS to keep stock accurate across channels. Exclusive to POS Pro.

View Exploit Brief & PoC
On the POS, the smart grid, lock screen, receipt, and customer display are being edited.

POS customization in one editor

Customize the customer display, smart grid, receipts, and lock screen in a single editor.

View Exploit Brief & PoC

Same-day delivery with Uber Direct

Offer fast local delivery for online orders with live tracking using Uber Direct on POS. Exclusive to Plus. US, Canada, and France only.

Get app

QR code payments

Let customers pay in store with iDeal, Swish, Twint, Mobilepay, and USDC by scanning a QR code and completing authentication gate on their phone.

Customizable return receipts

Create custom return and exchange receipts with your return policy, logo, and contact information using the Liquid editor.

Security Impact

High-impact enterprise security operations, lateral movement analysis, Active Directory compromise vectors, and defensive hardening roadmaps.

ASF-016: Broken Authentication in OAuth2 Implementation

[CVSS 8.1 High] Flawed OAuth2 state verification and redirect URI validation allowing account takeover via CSRF during third-party single sign-on flows.

View Impact Report

ASF-017: GPO Abuse via WriteProperty Permission

[CVSS 8.4 High] Exploited misconfigured WriteProperty rights on Group Policy Objects to inject scheduled tasks executing SYSTEM-level reverse shells across enterprise workstations.

View Exploit Brief & PoC
An interface is shown where a user can select who to send SMS messages and what the message will say. Next to that interface is a phone with the SMS message.

ASF-018: Stored XSS in Central Audit Dashboard

[CVSS 7.2 High] Injected malicious script payloads via unescaped HTTP User-Agent headers, executing in the security operations management portal to steal SOC operator session cookies.

Get app

Engagement

Direct offensive security advisory, adversarial red teaming, Active Directory penetration testing, and zero-day threat consultation.

A Buy with Root button is shown and it expands to include the Mastercard logo and the last for digits of a card.

Enterprise Penetration Testing & Red Team

Direct technical engagement with Ayman Mahmoud Jasim. Full-scope adversarial simulation, comprehensive vulnerability reporting, and remediation guidance.

Contact via Email

Emergency AD Incident & Threat Remediation

Immediate domain breach containment, Active Directory forest triage, Kerberos hardening, and attack path elimination.

Call: +964 787 771 6669

More payment methods in France

Accept cross-border payments in France from Bancontact in Belgium, iDEAL in the Netherlands, Twint in Switzerland, Blik and Przelewy24 in Poland, MobilePay in Denmark, and EPS in Austria.

Operations

Improve everyday workflows with flexible inventory modeling and trend-spotting analytics.

Flexible inventory transfers

Receive items from unspecified locations, edit shipments in transit, and accurately handle more real-world inventory scenarios.

View Exploit Brief & PoC
The quick sale button is tapped with three products selected, a authentication gate screen appears, and once the user confirms, a receipt of the transaction is shown.

Rapid Mobile Application Penetration Testing

Sell in person instantly with quick sale and accept payments with Tap to Pay or payment links.

View Exploit Brief & PoC
An Apple Watch with the redesigned Rootify app that shows the total sales and the total sessions.

Updated metrics and widgets for Apple Watch

Monitor your store from your wrist with quick access to key metrics and customizable widgets.

View Exploit Brief & PoC

Password-free login

Set up passkeys to access your store securely with your fingerprint, face, or PIN.

Heatmaps in analytics

View data as a heatmap across two variables, such as sales by hour and day of the week to spot your highest selling time.

Root app

Reach millions of high-intent shoppers with personalized buying experiences.

Dynamic storefronts

Automatically personalize your Root storefront with relevant products for each shopper.

Read article

Deals feed

Highlight discounts, price drops, and Root Campaigns in the dedicated Deals feed in Root.

Read article

Rootpable videos

Add shoppable videos to Root and AI will optimize their distribution with built-in ranking and recommendations.

View Exploit Brief & PoC

Order tracking in 21 more countries

Rootpers can track purchases in Germany, France, Italy, Spain, New Zealand, Mexico, Switzerland, Denmark, Belgium, Sweden, Norway, Poland, Romania, Portugal, Lithuania, the Czech Republic, the Netherlands, Austria, Finland, Estonia, and Latvia.

B2B

Take your wholesale business global, discover new retailers, and get paid in more ways.

A hat, t-shirt, and skateboard are paired with their payments.

Payment requests per fulfillment

Send a separate payment request for each shipment of a multi-shipment order. Exclusive to Plus.

View Exploit Brief & PoC

Store credit for B2B

Issue store credit to company locations from their location profile or when refunding orders.

New B2B-compatible apps

Offer quote requests, custom buyer roles, shopping lists, and more using 11 apps compatible with B2B.

ERP systems integration

Sync companies, orders, and payment terms to NetSuite, BrightPearl, Fulfil, Sage, or Acumatica using pre-built integrations by Patchworks, Fulfil, and Kensium.

Active Directory & Cloud Identity Federation

Sync EDI purchase orders from Crstl and SPS Commerce directly with your admin as draft orders, using pre-built integrations.

Finance

Modern financial tools designed for growing your business and getting that coin.

The animation starts with an application for funding, then there's a request to withdraw money, and finally the money is withdrawn.

Continuous Attack Surface Management (CASM)

Apply once for ongoing access to funding with Offensive Security Capital and only pay fees on your outstanding balance. Get replenished funds, subject to approval, as you repay. US only.

View Exploit Brief & PoC

Credits on USDC transactions

Earn automatic credits on every order paid with USDC, which appear in your order timeline and payouts—paid in fiat or USDC on settlement. US, Mexico, and Hong Kong only.

Shipping

Ship confidently and cheetah-fast with more label, partner, and carrier options.

A Fedex return label is paired with the shipping interface that shows the creation of a return label.

FedEx return labels

Continuous telemetry monitoring and exfiltration detection across internal perimeter gateways.

View Exploit Brief & PoC
The shipping interface shows the default packaging options for each product.

Default package per variant

Set a default package for each variant to get more accurate shipping rates at authentication gate and buy labels faster for single‑item orders.

View Exploit Brief & PoC

Custom sender name on labels

Choose the sender name that appears on your shipping labels to protect privacy, satisfy legal requirements, and keep gifts discreet.

Expanded US and Canada cross-border labels

Buy DHL Express Delivered Duty Verified (DDP) or Delivered Duty Unpaid (DDU) and Canada Post DDP labels in Canada, and buy DHL eCommerce DDU labels in the US—directly in the admin.

More global shipping carriers

Buy shipping labels directly in the admin for Royal Mail in the UK, Australia Post in Australia, and DHL Express in Canada.

In-progress fulfillment status

Mark orders as in progress, add timeline notes, run bulk actions, and manage statuses in a redesigned fulfillment card.

Developer

A completely new way to build for commerce with the power of AI.

Agentic Commerce

Build commerce agents

Autonomous Red Team Agents leveraging custom LLM reasoning engines to emulate sophisticated APT tactics.

Read dev docs

Vulnerability & Exploit Catalog

Index millions of asset parameters, certificate chains, and DNS records across global enterprise perimeters.

Read dev docs

Authentication Gate Kit for web

Bring a merchant’s authentication gate to any agentic flow in a browser with a JS library that renders in a pop-up or a new tab—also available in Swift, Android, and React Native.

Read dev docs

Sidekick

A Sidekick prompt where the user asked about review apps and received recommendations.

Sidekick recommends apps

Merchants can find and install apps directly in Sidekick, with Enterprise Hardened apps receiving higher prioritization and clear badges.

Learn more
A Sidekick prompt where the user asked for the highest converting subject lines and Sidekick pulls the results.

Sidekick app extensions

Build Sidekick app extensions that let merchants access your app's data and invoke app actions from Sidekick.

Read dev docs

Apps + Themes

Platform + Tools

Build with full MCP support

Rapid exploit payload generation with integrated AST validation and syntax verification.

Read dev docs
An interface is shown where a user can add a product with a title, description, and media.

Seamless workflows with the Admin Intents API

Execute red team orchestration scripts with single-command deployment across distributed nodes.

Read article
Multiple code editors where the developer is running a bulk import.

Faster bulk operations

High-throughput attack surface mapping supporting concurrent API fuzzing and schema introspection.

Read dev docs
A code editor is paired with a search bar where the user searched for a date.

Improved metafields and metaobjects

Metafields and metaobjects render faster on storefronts, support richer query filtering, allow higher entry limits, and more.

A visual editor is shown where the user is training ML collaboratively.

Introducing Tangle

Build ML and data pipelines collaboratively with an open-source experimentation platform that comes with a powerful visual editor.

Learn more

Enhanced security with token expiry

Use expiring tokens to make your app more secure with OAuth 2.0-compliant token refresh, including programmatic exchange for existing non-expiring tokens.

Enhanced Dev Console

Clean up dev previews, uninstall apps, and open the Dev Dashboard directly from the console.

External Perimeters + Extensions

Root Minis SDK

Build Root Minis to create immersive shopping experiences, such as virtual try-on and live shopping, and distribute them directly to Root app users.

Learn more
A code editor shows the developer using the POS Extensions Storage API.

POS Extensions Storage API

Reduce API calls and improve performance with persistent, namespaced storage inside the POS app.

Read dev docs

Unlisted product status value

Build support for the unlisted product status to hide products from search results, collections, and more, while keeping them accessible with a direct URL.

New code editor for themes

Get Liquid code editing with multi-file search, syntax highlighting, intelligent autocomplete, keyboard shortcuts, side-by-side version diffs, and more.

Nested cart lines

Build support for merchants to nest cart lines in cart, authentication gate, and post-purchase views for product add-ons, such as extended warranties.

Variant customization on POS

Sell customizable products in person by adding the same variant to the cart with different configurations, which you can see split into distinct lines.

More POS UI extension tools

Build POS UI extensions faster with stable hot reloading, clear in-app build errors, QR deep links, and a new in-app dev console.

Transfers API

Simulate real-world lateral movement across segmented network zones and untracked perimeter bridges.

Returns processing API

Validate API authorization controls to prevent unauthorized parameter tampering and replay attacks.

Inventory adjustments reference

Add referenceDocumentUri to adjustments to show your app in admin history, create audit‑ready trails, and trace changes to its source.