Security without the snark.

We’re a small group of reverse engineers, vulnerability researchers, tool developers and overall good human beings that specialize in tailored solutions for government and large enterprises.

No arrogance. No flippancy.

Just quality results from people you can actually talk to.

What We Do

Hacking for Good

Since 2012, we’ve responded to incidents, received multiple DARPA Research Projects and written custom tools that both inform and protect. Here’s what we do:

  • Narf Labs

    Custom design, architecture and implementation that meets and exceeds your security requirements. Whether commercial or government, help us help you take over the world.

  • Embedded / Mobile RE+VR

    We’re IoT experts that will answer the questions you didn't know you needed to ask and tackle the unknown unknowns (except for Godel’s incompleteness theorem—you’ve got us there).

  • Secure Design

    Let’s face it, “vulnerability happens”. We’ll help you address issues before they become problems.

    That way vulnerability happens less.

  • App Security Management

    Shipping insecure code is like showing up to dinner without pants. Nobody wants that.

    Bring us on to think like attackers before attackers can think like attackers and attack.

1 / 4

  • Incident Response

    Got a problem? Just shine the Narf signal into the sky and we’ll swoop in to remediate and mitigate (wham! pow! bam!) while thwarting future hackers. We’ve done this for some of the largest U.S. companies and we can do it for you. We’ve got your back.

  • Technical, Security-Cognizant Japanese Translation & Localization

    With a presence in Tokyo and fluent/native Japanese speakers, we speak tech security in Japanese as well as we do in English.

    問題ないよ

  • Forensic Discovery & Due Diligence

    Think CSI for cyber investigations (minus the terrible theme song and Caruso’s cheesy one-liners). Publicly we’ve collaborated with Basis Technologies on Autopsy and The Sleuth Kit (TSK) and privately we’ve conducted forensic discovery on behalf of some of the largest corporations in the world. Ask about our mobile and government offerings.

  • Penetration Testing

    We have an average of 0.8 DEF CON CTF black badges per employee. That means we’ve got the know-how to prevent you from getting screwed.

What We've Done

It might seem like magic, but it's just good ol' fashioned hard work and experience.

Tailored Malware RE

Put Narf’s Reverse Engineering (RE) experience to task for your malware reverse engineering needs.

More info

DARPA's Cyber Grand Challenge (CGC)

Check out CGC’s website and DARPA’s CGC Github, including some contributions from Narf.

More info

BBemu - A Baseband Emulation Framework

A huge body of security research has been focused on studying what runs on our smartphones’ Application Processors (APs). APs run the software most people are familiar with: Android, iOS, Windows Phone, BlackBerry OS, Symbian, webOS, etc.

More info

Custom Embedded RE & Debugging

Narf has years of experience voiding warranties, debugging things that don’t want to be debugged and leveraging hardware for unintended purposes.

More info

Trusted Stack / ELFBAC

Critical infrastructure is at risk. Fortunately, the U.S. Department of Energy funds efforts to meaningfully change the status quo.

More info

Kensa - Provably Secure Anti-RE

There is a large body of work devoted to program obfuscation (e.g. Obfuscator-LLVM, any DRM scheme).

More info

Private Information Retrieval (PIR) for Network Sensors

Traditional Private Information Retrieval (PIR) implementations focus on a client / database server model where the client has secret information in the database that must be protected even from database administrators.

More info

Professional, Technical and Security-Cognizant Japanese Translation and Localization

English-speaking investigators have long enjoyed the benefits of Autopsy, a free open source digital forensics suite built on The Sleuth Kit (TSK) and offered by Basis Technologies.

More info

Embedded Device Exploitation (EDE)

Narf is the exclusive licensee of Tactical Network Solutions’ Embedded Device Exploitation (EDE) course for the Japanese market.

More info

Symbolic Firewall

Narf has been awarded a patent on something we call Symbolic Firewall.

More info

Mobile Vulnerability Research (VR)

Narf knows mobile, and in particular, Android.

More info

Custom Static Analysis Tools

Narf are experts in Clang/LLVM’s plugin architecture. In particular, we have developed and delivered custom Clang “checkers”.

More info

Tailored App Assessments & Penetration Tests

Narf has a 100% success rate when it comes to Penetration Tests. Hire us if you think your network can take us down a notch. Better yet: hire us anyway.

More info

Tailored Forensic Services

Narf has years of experience in both forensics and anti-forensics toolkits, with an emphasis on the mobile space (Android in particular).

More info

Who We Are

Results Over Cyber-BS

Since 2012, we’ve responded to incidents, received multiple DARPA Research Projects and written custom tools that both inform and protect.

We believe that horse masks channel creativity and office fedoras are the new dunce caps.

Get In Touch

We’ll take care of your security while you take over the world

You know what to do here :) Looking forward to connecting!