Security Research
Real-world security research covering DAST, AI-assisted vulnerability analysis, attack chain modeling, and engineering benchmarks.

How we went from broken session tokens and missed vulnerabilities to a fully authenticated, optimized DAST pipeline — and every lesson learned along the way.

HAR files captured from browser traffic can easily exceed 25 MB, but ZAP only reads request and response fields. By stripping everything else, you can reduce a 25 MB HAR to ~500 KB with zero loss of scan coverage.

How recording real browser traffic with the Corefix Extension and feeding it into ZAP's automation framework transforms DAST coverage from surface-level to deep.

Processing time, task completion, and reliability data from running 247 real-world security findings through 21 LLMs - from Claude and GPT-5 to Bedrock and open-source models.

The engineering behind intelligent ZAP context building — from raw HTML to authenticated scans, automatically. No manual setup required.

We fixed ZAP's scan policy and achieved 700% better SQL injection detection. Then we discovered five more configuration layers silently breaking real-world scans.
Discover how Corefix helps security teams identify, prioritize, and remediate vulnerabilities across cloud, web, code, and infrastructure environments.
Visit Website →Setup guides, scanner integrations, workflows, remediation automation, API references, and complete product documentation.
View Documentation →See upcoming releases, planned features, product improvements, and the future direction of Corefix.
View Roadmap →