KNULL / OPENING CHANNEL

Show us what
you broke.

No degree. No CV screening. One piece of work.

Before you start: do not test this site. Read the rules of engagement.

Register as an offensive security researcher. Six questions: handle, specialities, one piece of work, availability and contact.

See what we read
01 / WHAT WE READ

Your work
speaks first.

We open the link before we read the rest. A finding, a tool, a write-up, a research note nobody asked you to publish. It does not have to be famous. It has to be yours and it has to show how you think.

01

How you think

Not the payload. The reasoning that got you to it, what you ruled out on the way and the moment you decided the thing in front of you could be pushed further.

02

How you prove it

A finding nobody can reproduce is a story. We look for steps, evidence and an honest account of impact, including the times it turned out to be smaller than it looked.

03

How you write it

You will explain what you found to people who are not you, sometimes to people who will have to defend the budget to fix it. Clear beats clever, every time.

No degree is required and none is an advantage. Self-taught, dropped out, still studying, switching careers at forty: none of that is a question on this form, because none of it predicts what you can find.

02 / RULES OF ENGAGEMENT

Do not test
this site.

This is our production infrastructure. It holds other people's data: companies that told us what they are afraid of, and researchers who sent us their work and their contact details. It is not a target and it is not a CTF.

Not here, not as a demo, not to get our attention

  • No scanning, fuzzing or directory brute forcing.
  • No DNS zone transfers (AXFR) or subdomain takeover attempts.
  • No credential stuffing, no password spraying, no attempts against the console.
  • No injection payloads in these forms, "just to see what happens".
  • No denial of service, no load testing, no traffic you would not want logged.
  • No social engineering of anyone who works here.

Testing something you were not authorized to test is the one thing that closes an application here. We do this for a living: an unrequested scan is unmistakable in the logs, and it does not read as talent. It reads as someone who has not yet learned the part of the job that keeps clients.

If you already found something

Tell us, and stop there. Do not go deeper to measure the impact, do not pull data to prove it, do not check whether it works twice. Our disclosure contact is in security.txt.

We do not run a bug bounty and we do not pay for reports. We read every one, we answer, and we credit you publicly if you want the credit. Reporting well is itself a piece of work we can evaluate.

Everything you want to prove, prove it where you were allowed to: your own lab, a CTF, a program that authorized you, a tool you wrote, a target that said yes in writing. That is what the form below is for.

03 / WHAT HAPPENS

After you
press send.

  1. You get a reference code

    Keep it. It identifies your registration without us having to ask for your personal details again.

  2. A person reads your work

    Not a filter, not a keyword scan, not a model. Someone who does this work opens your link and reads it.

  3. We answer either way

    If it is a no, you get a no. Silence is what the companies we were rejected by did to us, and we are not going to reproduce it.

  4. If it is a yes, we talk scope

    A conversation about how you work, then a real engagement with an agreed scope, written authorization and someone alongside you the first time.

We were turned down for the wrong reasons.
We are not going to turn you down for them.
Register
KNULL / DATA
DATA / CONTACT

Only what
we need.

What we store

Your handle, email, the public link to your work, the specialities you pick, your availability, your time zone and whatever context you choose to write. Your consent and its date are stored with it.

Why

To review your registration and to contact you about working together. These forms are not used for marketing lists and your details are not sold or shared.

Where

On the server that hosts this site, in a database that is not reachable over HTTP. No analytics, no tracking cookies, and no AI model receives your answers.

What not to send

No passwords, no secrets, no client data, no unpublished vulnerability details belonging to someone else. Link only to work you are allowed to show.

Ask us to delete your registration at any time and we will, quoting the reference code you received.