We don't sell you security. We demonstrate it.
Vulnerability research recognized by Microsoft and covered by specialized press, advisory on your security posture, and advanced training led by active researchers.
What we do
Security advisory & architecture
Posture audits, architecture reviews and strategic guidance to align your security with your real exposure, not a generic checklist.
RESEARCHVulnerability research & visibility
Original offensive research: vulnerability discovery, security product bypasses, responsibly published to build your credibility and generate opportunities.
TRAININGCyber & AI training
Advanced Cyber & AI training, led by active researchers and AI experts, to upskill your teams on real-world threats and AI applied to security.
What Kopnex is
Kopnex is a cybersecurity firm founded by Ruben Enkaoua, an offensive security researcher specialized in vulnerability research, EDR/XDR bypass and attack simulation (MITRE ATT&CK).
Our belief: the best proof of skill isn't a sales pitch, it's a vulnerability found, fixed with the vendor, then published. That's what fuels both our advisory work and our visibility, and that of the companies who choose to associate with our research.
Our research cited by
Vulnerabilities fixed by vendors, then covered by authorities and specialized press.
MSRC
Official Microsoft Security Response Center acknowledgment of CVE-2025-59214.
The Hacker News
Research cited in a roundup on privilege escalation.
DC3 / DCISE
Cyber Threat Roundup from the Department of Defense Cyber Crime Center.
Cybersecurity News
Coverage of the Windows zero-click NTLM leak.
Latest articles
All articles →Task Scheduler: Poisoning and Tampering with Event Logs
Two Defense Evasion techniques in the Windows Task Scheduler let an attacker falsify a task's metadata and overflow the event log that records it.
Read the article → May 20, 2025CVE-2025-59214: When a Microsoft Patch Fixes Nothing
The patch for CVE-2025-50154 didn't work at all. Here's how the same technique led to a new CVE.
Read the article → April 8, 2025CVE-2025-50154: Zero-Click NTLM Leak and a Microsoft Patch Bypass
A previous patch blocked a known NTLM leak vector. Here's how it could be bypassed, with zero interaction from the victim.
Read the article →