Twenty Years
Zero Complacency.
ASEC is a Toronto-based offensive-security consultancy. We deliver adversary-class engagements to enterprises, defence contractors, and critical-infrastructure operators across Canada and internationally.
Delivering offensive engagements since 2015
DC416 DEF CON chapter, Toronto, founded by Nick Aleks
CADSI, ACDC, CCTX, and IN-SEC-M membership
Offensive security across every attack surface.
Penetration Testing
Adversary-class assessments across web applications, APIs, mobile, cloud, and network infrastructure. Scope includes GraphQL, REST, gRPC, SOAP, AWS, Azure, and GCP targets. Findings are mapped to MITRE ATT&CK and include exploitation evidence.
Red Team Operations
Objective-based adversary simulation for enterprises and defence contractors. Full-chain engagements: initial access, lateral movement, privilege escalation, and objective attainment. TIBER-EU methodology available for financial-sector clients.
Drone and Autonomous Systems
Canada's only commercial offensive-security practice dedicated to UAV, UGV, and autonomous-systems attack surfaces. Targets include ArduPilot, PX4, MAVLink link-layer, GCS software, STANAG 4586 interfaces, and RF link exploitation.
We build the tools the industry trains on.
Three open-source projects with combined 1,109 GitHub stars. Used by penetration testers, security researchers, and red teams globally.
Damn Vulnerable Drone
An intentionally vulnerable drone-hacking simulator. The industry-standard open-source environment for learning UAV attack surfaces: MAVLink injection, GPS spoofing, GCS exploitation, and RF link analysis.
GitHubCrackQL
GraphQL password-cracking and oracle-exploitation tool. Used by penetration testers worldwide to identify authentication weaknesses in GraphQL APIs.
GitHubGraphQL Threat Matrix
A structured taxonomy of GraphQL attack classes: introspection abuse, injection, denial-of-service, batching attacks, and authorization bypass. The reference framework for GraphQL security assessments.
GitHubNick Aleks
Chief Hacking Officer
Nick Aleks is the founder and Chief Hacking Officer of ASEC. He has spent over a decade delivering offensive engagements for enterprises, defence contractors, and critical-infrastructure operators across Canada and internationally.
Nick authored two books published by No Starch Press: Black Hat GraphQL (2023) and Black Hat Bash (2024). He created Damn Vulnerable Drone, the open-source UAV attack-surface simulator now used by security researchers and red teams globally. He founded DC416, the DEF CON Group chapter for Toronto, in June 2016. The chapter reaches 2,880 members and hosts the Trace Labs Missing Persons OSINT CTF.
Nick has spoken at MapleSEC, GraphQL Summit, CanSecWest, and Black Hat. He is a member of CADSI, ACDC, CCTX, and IN-SEC-M.
Full ProfileASEC Research and Labs
Adversarial Testing of Autonomous Platforms: The ArduPilot Attack Surface
A technical primer on ArduPilot's attack surface, covering MAVLink injection, GCS exploitation, and RF link vulnerabilities. Co-authored with the Damn Vulnerable Drone research.
ReadYour Untested GraphQL API is a Ticking Time Bomb
GraphQL introspection, batching abuse, and authorization bypass techniques. A practitioner's guide to the most-missed vulnerabilities in modern API surfaces.
ReadFive Core Principles of Fighting Back in Security
Nick Aleks keynote at MapleSEC 2022. Covers the ASEC offensive philosophy: active defense, adversary emulation, and why passive security fails against determined attackers.
ReadIndustry memberships and alliances.
ASEC is a member of four Canadian defence and security industry bodies.
Canadian Association of Defence and Security Industries
Federal defence procurement. ASEC is positioned on the procurement-facing side of the Canadian defence industry, with access to DND-connected supply chains and defence-sector buyers.
Aerospace, Cybersecurity, and Defence Coalition
Canadian-sovereign defence signal. Differentiates ASEC from multinational supply-chain competitors and positions the firm as a domestically accountable security partner.
Canadian Cyber Threat Exchange
Threat-intelligence sharing with Big Six banks, major telcos, and critical-infrastructure operators. ASEC contributes to and receives intelligence through this network.
Innovation, Security and Excellence in Cybersecurity
Canadian-content procurement directory. Surfaces ASEC to in-country capability buyers and positions the firm within the vetted Canadian cybersecurity supplier base.
Ready to engage?
Contact us to discuss your offensive-security requirements. We work with enterprises, defence contractors, and critical-infrastructure operators.