Driving security change through research and consulting
Security Research Labs is a security research and consulting firm in Berlin. Since 2010 we have measured things the industry took on trust: whether Android phones carried the patches they reported, whether mobile networks implement the protections their standards define, whether an EDR makes an enterprise safer. Often they did not.
The systems we work on
Write-ups between 2010 and 2026, coloured by the system each is about. Hatched bands are tool releases, guides and company notes, and work not tied to one system.
Enterprise IT & cloud
Identity systems are the usual route from one foothold to the whole estate.
Identity, endpoints, cloud platforms, SaaS, and the internal networks that connect them.
Mobile & telco
A5/1 in 2010, SIM cards in 2013, 5G RAN since: the estate we have measured longest.
Core networks, interconnect, RAN, SIM, handsets, and mobile applications.
Blockchain
A Polkadot runtime under continuous review since 2019, and the Ethereum patch gap measured in 2019.
On-chain applications, runtimes, bridges, and the cryptography underneath.
AI systems
The deployment breaks before the model does.
Agents and assistants, tool and retrieval boundaries, MLOps pipelines, model artifacts, and the identity plumbing behind them.
Firmware & devices
BadUSB in 2014, and the first open-source Hexagon baseband fuzzer in 2025.
Boot chains, firmware, basebands, embedded runtimes, and connected hardware.
Payments & fintech
Broken on stage at 32C3 in 2015, and again on an Android terminal in 2022.
Card and account infrastructure, POS and EFT systems, and financial platforms under DORA.
Latest research
Beyond Fable: can a local LLM replace cloud AI for security code reviews?
Across four models and two production codebases, a ~3B-active-parameter model on a laptop matched a frontier cloud model on raw finding count in under 90 minutes per codebase, with no source file leaving the machine. Metadata, step prompts and step-level findings, which can carry line references and short code excerpts, do cross.
How we did it
Controlled comparison of four models over two codebases (~150 and ~85 source files) with a fixed harness. Two further models acted as orchestrators rather than subjects, which is why the count is four and not six.
The people who do the work
Everyone here has published research on this site. The people who publish are the people on the engagement, so you can read someone's work before you meet them.
Aly Anwar
Regina Bíró
Fabian Bräunlein
Daniel Corak
Genco Altan Demir
Niklas van Dornick
Nicholas Farnham
Luca Glockow
Marc Heuse
Lara Kaiser
Mahmoud Anas Khalifa
Jakob Lell
Lisa Lobmeyer
Balthasar Martin
Matthias Marx
Luca Melette
Louis Merlin
Tobias Müller
Yvette Muszynski
Linus Neumann
Karsten Nohl
Dominik Oepen
Nils Ollrogge
Nina Piontek
Bruno Produit
Jannes Quer
Rene Rehme
Jakob Rieck
Alberto del Rio
Folkert Saathoff
Erdoğan Yağız Şahin
Ben Schlabs
Daniel Schmidt
Rachna Shriwas
Felix Siewert
Vincent Ulitzsch
Julian Ferdinand Vögele
Robert Waniek
Florian Wilkens
Sina Yazdanmehr
Stephan Zeisberg