Willis Vandevanter

currently: ai security engineer

previously: Trail of Bits, R7, Google SoC. Multiple startups. Ran my own consultancy for 5.5 years

  1. GitHub
  2. LinkedIn
  3. RSS
  4. Blog Posts
  5. Presentations + Trainings
  6. Advisories
  7. Search
  8. Archives
    1. Dark Mode

2026

active defense and adversarial agents: service sandbagging

Saturday, August 15, 2026
active defense and adversarial agents: service sandbagging

active defense and adversarial agents: context bombs

Thursday, August 13, 2026
active defense and adversarial agents: context bombs

active defense and adversarial agents: exploding search space (academic)

Wednesday, August 12, 2026
active defense and adversarial agents: exploding search space (academic)

active defense and adversarial agents: malicious skills

Monday, August 10, 2026
active defense and adversarial agents: malicious skills

active defense and adversarial agents: hostname beacon

Sunday, August 9, 2026
active defense and adversarial agents: hostname beacon

active defense and adversarial agents: token burn

Saturday, August 8, 2026
active defense and adversarial agents: token burn

active defense and adversarial agents: guardrail triggers

Friday, August 7, 2026
active defense and adversarial agents: guardrail triggers

rethinking threat models when the cost is tokens not time

Thursday, August 6, 2026
rethinking threat models when the cost is tokens not time

Bespoke C2 - LLM era

Wednesday, August 5, 2026
Bespoke C2 - LLM era

MCP list caching and tool poisoning

Sunday, August 2, 2026
MCP list caching and tool poisoning

2025

Exploiting GraphQL Secondary Context Attacks

Thursday, July 10, 2025
Exploiting GraphQL Secondary Context Attacks

2022

Pulling Specific Files from the Trickest Inventory (or any Github project)

Friday, August 26, 2022
Pulling Specific Files from the Trickest Inventory (or any Github project)

🎉 burpsuite-project-file-parser v1.1 🎉

Thursday, July 21, 2022
🎉 burpsuite-project-file-parser v1.1 🎉

Building on an AppSec Pipeline with Burp Suite data - Part 2

Friday, June 17, 2022
Building on an AppSec Pipeline with Burp Suite data - Part 2

Building on an AppSec Pipeline with Burp Suite data - Part 1

Wednesday, June 8, 2022
Building on an AppSec Pipeline with Burp Suite data - Part 1

2019

SSRF Protocol Smuggling in Plaintext Credential Handlers : LDAP

Wednesday, February 6, 2019
SSRF Protocol Smuggling in Plaintext Credential Handlers : LDAP

2018

odle ruby gem: piping security data

Thursday, May 24, 2018
odle ruby gem: piping security data

2016

Exploiting CVE-2016-4264 With OXML_XXE

Sunday, October 2, 2016
Exploiting CVE-2016-4264 With OXML_XXE

Finding Hosts Using SSL Certificate Organization And Censys

Tuesday, September 27, 2016
Finding Hosts Using SSL Certificate Organization And Censys

Exploiting XXE In File Upload Functionality

Sunday, May 1, 2016
Exploiting XXE In File Upload Functionality

Cloud Metadata URL List

Monday, March 28, 2016
Cloud Metadata URL List

2015

XML Entity Cheatsheet - Updated

Thursday, December 24, 2015
XML Entity Cheatsheet - Updated

Blackhat 2015 Arsenal

Thursday, September 10, 2015
Blackhat 2015 Arsenal

Simple Ruby Exec with Open and Pipe

Tuesday, April 14, 2015
Simple Ruby Exec with Open and Pipe

Exploiting XXE Vulnerabilities in OXML Documents - Part 1

Wednesday, March 4, 2015
Exploiting XXE Vulnerabilities in OXML Documents - Part 1

ldapsearch notes

Wednesday, February 25, 2015
ldapsearch notes

Search all Github Repositories for an Organization

Friday, January 9, 2015
Search all Github Repositories for an Organization

2014

Searching Through Git Commits

Monday, October 6, 2014
Searching Through Git Commits

XML Entity Cheatsheet

Wednesday, September 3, 2014
XML Entity Cheatsheet

IPv6 DNS Guessing Notes

Tuesday, August 19, 2014
IPv6 DNS Guessing Notes

Blackhat 2014 Arsenal Experience

Monday, August 11, 2014
Blackhat 2014 Arsenal Experience
© 2014 - 2026 Willis Vandevanter