Category
Engineering
How we build Ostorlab: AI agents, scanning internals, and the engineering decisions behind them.
The True Cost of False Positives: Calculating the Engineering Tax of Noisy Scanners
False positives are an engineering-capacity problem, not only a scanner-quality problem. Learn how to measure their cost and evaluate the ROI of proof-of-exploit testing.
Sep 28, 2026
When Does an AI Scanner Become an AI Pentest?
Learn what separates AI-powered scanning from AI pentesting and how Ostorlab Deep Agentic Scan fo...
Jul 22, 2026
Source Code Security: From Signal to Validated Risk | Ostorlab
Learn how source code security testing works, why traditional SAST creates false positives, and h...
Jul 16, 2026
The App Was Never Opened
Agentic harnesses change what an LLM can do in mobile app security testing. On its own, a model c...
Jun 25, 2026
More in Engineering
Building an AI PR Reviewer Engineers Actually Trust
We built an AI-powered pull request reviewer, shut it down after hallucinations and false positives eroded developer trust, then rebuilt it with better models, broader context, and a more conservative agent architecture. This article shares what we learned about automated code review, why trust matters more than coverage, and how AI reviewers can help engineering teams reduce repetitive review work without replacing human judgment.
Jun 08, 2026
Threat Center v2: Staying Ahead of Vulnerabilities
The Threat Center provides essential updates for organizations to stay informed about security threats, offering actionable intelligence and detailed asset information to help users proactively protect their systems.
Oct 10, 2024
OXO Titan UI: Simplifying Security Scanning for Everyone
OXO Titan UI encapsulates OXO's capabilities within an accessible interface, democratizing advanced security scanning techniques. This article explores OXO Titan's journey from concept to reality, highlighting its key features and presenting a practical user workflow example.
Aug 26, 2024
🚀 OXO v1.0!
OXO version 1.0, is 10x times faster, supports ARM64 architectures, and is packed with improved capabilities like scanning multiple assets, simpler and powerful CLI.
Apr 29, 2024
Apple Privacy: A Comprehensive Guide to Privacy Manifest Files
This article offers a guide to Privacy Manifest files in Apple's ecosystem, stressing their importance for transparency and compliance, especially with the upcoming 2024 mandate, outlining steps for implementation, and underscoring their role in promoting user trust and adherence to regulations.
Apr 18, 2024
Enhancing PostMessage XSS Detection with Proxy Object Instrumentation
The article introduces a new method for detecting PostMessage Cross-Site Scripting (XSS) vulnerabilities using JavaScript Proxy objects, which enhances traditional dynamic fuzzing techniques.
Apr 04, 2024
Swift Under the Microscope: Practical Dynamic Instrumentation
Article on Swift Dynamic Instrumentation. The article explains the steps to perform dynamic analysis of Swift-based application, covering name mangling, Swift ABI & extraction of function arguments in Swift.
Mar 11, 2024
Strategies for writing super fast Python
In this article, we look at different ways to improve the performance of Python which is an interpreted language.
Apr 18, 2023
Fix it! at Ostorlab
Ostorlab's Fix it! practice is one of our most successful engineering practices helping us eradicate bugs and kill technical debt.
Feb 19, 2023
Tips and tricks for developing & debugging OXO Agents.
Tips and tricks to make your life easier when developing & debugging OXO Agents.
Aug 18, 2022