Vulnerability research & offensive security
Fuzzing, source review, exploit development, and hardening. The same techniques behind our CVE record, aimed at your codebase before an adversary aims theirs.
Independent security research · est. 2016 · 35.47° N, 97.42° W
Deep Fork Cyber is the security practice of Brian “geeknik” Carpenter — former criminal investigator, vulnerability researcher, and finder of flaws in Firefox, OpenSSL, PHP, Perl, tcpdump, WebKit, and dozens more.
Hundreds of CVEs credited across a decade of research — memory corruption, logic flaws, and protocol failures in software the internet runs on. Not scanner output. Reported, confirmed, fixed. Every identifier below links to the public record.
autonomous vulnerability hunting
Our flagship: a pipeline that hunts for vulnerabilities the way we would — around the clock, at a scale no human team can match. Machines handle the tireless part. A decade of exploit intuition decides what matters. Real bugs, found before someone less friendly does.
Visit cve.monster →Fuzzing, source review, exploit development, and hardening. The same techniques behind our CVE record, aimed at your codebase before an adversary aims theirs.
Applied mathematics and machine-learning engineering — from autonomous analysis pipelines to bespoke tooling. We build the systems other firms only put in slide decks.
Your security department, without the department. Architecture review, threat modeling, incident response, and a researcher on call who has seen how software actually breaks.
A former criminal investigator advising agencies, productions, and actors on how investigations and intrusions really work. Registered with the Oklahoma Film & Music Office.
The Deep Fork of the North Canadian River rises in Oklahoma City and works its way east across central Oklahoma — slow, muddy, and persistent. It is not in a hurry, and it gets everywhere. That is roughly our methodology.
Before security research, Brian Carpenter worked as a criminal investigator. That job teaches evidence chains, interviews, and the discipline of proving what actually happened — not what someone assumes happened. Since 2016 that discipline has been aimed at software, producing one of the more prolific independent vulnerability-research records in the field.
Engagements, retainers, and consulting inquiries — one email reaches the researcher, not a sales team.
b@deepforkcyber.com