Aleks Security
Cyber Intelligence Inc.
ASEC is a Toronto-based offensive-security consultancy. We exist to deliver adversary-class engagements that give enterprises, defence contractors, and critical-infrastructure operators an accurate picture of their exploitable attack surface, before an adversary gets there first.
Founded in Toronto, Ontario
Delivering offensive-security engagements
Published open-source tools with 1,109+ combined GitHub stars
Nick Aleks
Chief Hacking Officer, Aleks Security Cyber Intelligence Inc.
Nick Aleks is the founder and Chief Hacking Officer of ASEC. He has spent over a decade delivering adversary-class offensive engagements for enterprises, defence contractors, and critical-infrastructure operators.
Nick authored two books with No Starch Press: Black Hat GraphQL (2023) and Black Hat Bash (2024). He created Damn Vulnerable Drone, the open-source UAV attack-surface simulator used by security researchers and red teams globally, with 402 GitHub stars. He maintains CrackQL and the GraphQL Threat Matrix, bringing combined open-source contributions to 1,109 GitHub stars.
Nick founded DC416, the officially recognised DEF CON Group chapter for Toronto, in June 2016. The chapter reaches 2,880 members and hosts the Trace Labs Missing Persons OSINT CTF, described as the world's first OSINT CTF for missing persons. DC416 marks its tenth anniversary in 2026.
He has spoken at MapleSEC, GraphQL Summit, CanSecWest, and Black Hat, and holds memberships in CADSI, ACDC, CCTX, and IN-SEC-M.
- Black Hat GraphQL (No Starch Press, 2023)
- Black Hat Bash (No Starch Press, 2024)
- MapleSEC 2022 Keynote: Five Core Principles of Fighting Back in Security
- GraphQL Summit: Advanced GraphQL Hacking Techniques
- CanSecWest DOJO: Drone Penetration Testing
- Black Hat: API and GraphQL Security
- 2025 US Drone Security Conference (title TBD)
- DC416 DEF CON Group Toronto, founder (June 2016)
- Trace Labs Missing Persons OSINT CTF, host chapter
Practice Areas
Application and API Penetration Testing
ASEC delivers penetration testing for web applications, mobile applications, and APIs including GraphQL, REST, gRPC, and SOAP. Assessments include authentication bypass, injection vulnerabilities, authorization weaknesses, business-logic flaws, and platform-specific attack classes. Cloud targets include AWS, Azure, and GCP infrastructure and serverless functions.
Red Team and Adversary Simulation
Objective-based adversary simulation for enterprises and regulated-sector clients. Full-chain engagements cover initial access, persistence, lateral movement, credential access, and objective attainment. TIBER-EU methodology is available for European Central Bank-compliant financial-sector mandates.
Drone, UAV, and Autonomous Systems
ASEC is the only Canadian commercial firm with a dedicated drone and autonomous-systems offensive-security practice. Attack surfaces include ArduPilot and PX4 flight-controller firmware, MAVLink protocol injection, GCS software exploitation, STANAG 4586 interface assessment, RF link analysis, GPS spoofing, and drone-swarm coordination vulnerabilities.
Cloud and Infrastructure Security
Cloud security assessments for AWS, Azure, and GCP environments. Scope includes IAM privilege escalation, container and Kubernetes security, serverless function exploitation, secrets management weaknesses, and network segmentation gaps.
Network and Physical Security
Internal and external network penetration testing covering perimeter egress controls, VLAN hopping, protocol-level attacks, and legacy-system exploitation. Physical security assessments include access control bypass, tailgating simulation, and badge-cloning attacks.
DC416 DEF CON Group
DC416 is the officially recognised DEF CON Group chapter for Toronto. Nick Aleks founded the chapter in June 2016. It marks its tenth anniversary in 2026.
DC416 hosts monthly meetups at 100 Queens Quay East, Toronto, and runs the Trace Labs Missing Persons OSINT CTF, the world's first OSINT CTF for missing persons. The chapter reaches 2,880 members across the Toronto security community.
- Members
- 2,880
- Founded
- June 2016
- Meetup Rating
- 4.7 / 5.0
- Anniversary
- 10 years, 2026
- Founder
- Nick Aleks, sole founder
Memberships and Alliances
ASEC is a member of four Canadian defence and security industry bodies: CADSI, ACDC, CCTX, and IN-SEC-M.
Canadian Association of Defence and Security Industries
CADSI is the national industry association representing Canadian companies in the defence and security sectors. ASEC membership positions the firm on the procurement-facing side of the Canadian defence industry, providing access to DND-connected supply chains and federal defence-sector buyers. CADSI membership is a procurement signal for government and Crown-corporation clients evaluating Canadian-sovereign security suppliers.
Aerospace, Cybersecurity, and Defence Coalition
ACDC is a Canadian-sovereign defence alliance that differentiates member firms from multinational supply-chain competitors. ASEC membership positions the firm as a domestically accountable security partner for Canadian aerospace and defence clients where sovereignty and supply-chain provenance are procurement requirements. Increasingly relevant for defence contractors subject to national-security supply-chain reviews.
Canadian Cyber Threat Exchange
CCTX facilitates threat-intelligence sharing among Canada's largest enterprises, including Big Six banks, major telecommunications providers, and critical-infrastructure operators. ASEC contributing membership provides two-way intelligence exchange access: ASEC offensive research informs the network, and CCTX intelligence informs ASEC engagement scoping for financial-sector and critical-infrastructure clients.
Innovation, Security and Excellence in Cybersecurity
IN-SEC-M is the Canadian-content procurement directory for cybersecurity service providers. ASEC membership surfaces the firm to in-country capability buyers conducting vendor due-diligence for federal and provincial procurement mandates. Buyers seeking domestic-content cybersecurity services consult IN-SEC-M as a vetted supplier registry.
Ready to engage?
Contact us to discuss your offensive-security requirements. We work with enterprises, defence contractors, and critical-infrastructure operators.