Independent security research · est. 2016 · 35.47° N, 97.42° W

Hundreds of CVEs trace back to a quiet river in Oklahoma.

Deep Fork Cyber is the security practice of Brian “geeknik” Carpenter — former criminal investigator, vulnerability researcher, and finder of flaws in Firefox, OpenSSL, PHP, Perl, tcpdump, WebKit, and dozens more.

The record

We find what ships broken.

Hundreds of CVEs credited across a decade of research — memory corruption, logic flaws, and protocol failures in software the internet runs on. Not scanner output. Reported, confirmed, fixed. Every identifier below links to the public record.

Current focus

cve.monster

autonomous vulnerability hunting

Our flagship: a pipeline that hunts for vulnerabilities the way we would — around the clock, at a scale no human team can match. Machines handle the tireless part. A decade of exploit intuition decides what matters. Real bugs, found before someone less friendly does.

Visit cve.monster →
Services

One firm, four ways to hire it.

Vulnerability research & offensive security

Fuzzing, source review, exploit development, and hardening. The same techniques behind our CVE record, aimed at your codebase before an adversary aims theirs.

AI, automation & algorithms

Applied mathematics and machine-learning engineering — from autonomous analysis pipelines to bespoke tooling. We build the systems other firms only put in slide decks.

Fractional security team

Your security department, without the department. Architecture review, threat modeling, incident response, and a researcher on call who has seen how software actually breaks.

Law enforcement & film consulting

A former criminal investigator advising agencies, productions, and actors on how investigations and intrusions really work. Registered with the Oklahoma Film & Music Office.

Currently consulting
About

The river, and the investigator.

The Deep Fork of the North Canadian River rises in Oklahoma City and works its way east across central Oklahoma — slow, muddy, and persistent. It is not in a hurry, and it gets everywhere. That is roughly our methodology.

Before security research, Brian Carpenter worked as a criminal investigator. That job teaches evidence chains, interviews, and the discipline of proving what actually happened — not what someone assumes happened. Since 2016 that discipline has been aimed at software, producing one of the more prolific independent vulnerability-research records in the field.

Contact

Put an investigator on your side of the table.

Engagements, retainers, and consulting inquiries — one email reaches the researcher, not a sales team.

b@deepforkcyber.com