ASEC · Toronto, Canada
Speed wins cyber,
we hit first.
Offensive security for drones, robotics, and autonomous systems, inside a full-stack practice.
Field notes
News
View all →Open source
Open-source projects
github.com/nicholasaleks →
821Damn Vulnerable Drone
Intentionally vulnerable drone hacking simulator on the ArduPilot/MAVLink stack. A full lab for hands-on drone security.
352CrackQL
GraphQL password brute-force and fuzzing utility for testing API authentication at scale.

SiKW00F
Drone SiK radio detection and MAVLink telemetry eavesdropping toolkit.

Infected Drones
A collection of vulnerabilities and exploits against modern ground control stations.
What we do
Full-stack offense
Drone, UAV and Robotics Testingthe wedge
Adversarial testing of autonomous platforms: RF and MAVLink links, firmware, hardware, and ground control.
Adversarial Assessments
Web and API (GraphQL specialist), network, cloud, mobile, IoT, and physical penetration testing.
Security Consulting
Threat modeling, NIST maturity, compliance readiness, vendor risk, and virtual CISO.
Incident Response
Threat hunting, IR program assessment, playbook development, forensics, and table-top exercises.
The ASEC Platform
Continuous security testing, attack surface management, patch validation, and Nuclei test development.
Experience
Member of





Who breaks it
Nick Aleks
Chief Hacking Officer
Co-author of Black Hat GraphQL and Black Hat Bash, and the maker of Damn Vulnerable Drone, the open ArduPilot and MAVLink lab the industry trains on. The offensive work here is his, not a slide deck.
Founder of DC416 — Canada's largest hacker community. A 2,880-member Toronto DEF CON group, ten years running.
