& Control
WE ATTACK
WHAT OTHERS
PROTECT.
Full-spectrum offensive security: penetration testing, red team engagements, security consulting, and adversarial training across web, cloud, mobile, IoT, building automation, and the autonomous-systems niche only ASEC owns in Canada.
& Control
Control Station
Firmware
Navigation
Supply Chain
ASEC is the only Canadian commercial firm with a credible drone, UAV & robotics offensive-security practice, led by the author of the open-source ArduPilot / MAVLink drone-hacking simulator the rest of the industry trains on.
Autonomous-Platform Vectors
- VECTOR 01 // RF C2
RF Link & C2 Exploitation
Adversarial assessment of the radio-frequency command-and-control channel: telemetry intercept, frequency-hopping analysis, replay attacks, link-layer crypto review, and C2 takeover scoping.
- VECTOR 02 // GCS
Ground Control Station Pentest
QGC, Mission Planner, and custom GCS surfaces: auth bypass, mission-file injection, log tampering, web/desktop attack surface against the operator environment.
- VECTOR 03 // FIRMWARE
Autopilot Firmware Extraction
JTAG / UART / SWD firmware extraction, ArduPilot and PX4 stack fuzzing, parameter-table tampering, secure-boot bypass scoping, firmware-supply-chain integrity.
- VECTOR 04 // NAV
GPS / INS Spoofing
GPS spoof and jam resilience testing, INS drift exploitation, geofence-circumvention scoping, RTK / multi-constellation receiver attacks, sensor-fusion failure modes.
- VECTOR 05 // SUPPLY
Payload & Supply Chain
Payload-bay protocol audit, third-party SDK review, integrator firmware-integrity validation, dependency-graph supply-chain risk, drone-builder operational security.
- VECTOR 06 // ROBOTICS
Robotics & ROS Adversarial
ROS / ROS2 DDS-layer attacks, robot SDK fuzzing, motion-controller pentest, sensor-spoofing for UGV / UAV / industrial manipulators. Autonomous-systems redteam beyond drone-only.
Full Service Surface
- [01]
Adversarial Assessment
Pentest, physical, network, cloud, web/API (GraphQL specialist), mobile, IoT. Full-scope offensive engagements.
- Penetration Testing
- Physical Assessment
- Cloud · Web · API · Mobile
- IoT & Building Automation
- [02]
Security Consulting
Program development, threat modeling, vCISO oversight, vendor risk, compliance readiness. Strategic security guidance.
- Threat Modeling
- Maturity Assessment
- Virtual CISO
- Vendor & Vuln Programs
- [03]
Security Training
Executive awareness, secure development training, and ASEC online offensive-security courses. GraphQL Foundational + Advanced.
- Executive Awareness
- Secure Dev Training
- Foundational GraphQL
- Advanced GraphQL
Research / Open Source
The work the rest of the industry trains on. ASEC’s founding team publishes the tools, books, and simulators that define how the next generation of offensive security practitioners learn drone, GraphQL, and bash adversarial tradecraft.
Damn Vulnerable Drone
Intentionally vulnerable drone hacking simulator based on ArduPilot/MAVLink. A realistic environment for hands-on drone hacking, used by pentesters and researchers worldwide as the canonical training simulator for autonomous-systems offensive security.
github.com/nicholasaleks/Damn-Vulnerable-DroneCrackQL
GraphQL password brute-force and fuzzing utility. Adopted by GraphQL security researchers and bug bounty hunters.
github.com/nicholasaleks/CrackQLGraphQL Threat Matrix
The reference threat framework used by security professionals to research security gaps in GraphQL implementations.
github.com/nicholasaleks/graphql-threat-matrixBlack Hat GraphQL
Attacking Next-Generation APIs. No Starch Press, 2023. Co-authored with Dolev Farhi. The hands-on field manual for GraphQL adversarial testing.
nostarch.com/black-hat-graphqlBlack Hat Bash
Creative Scripting for Hackers and Pentesters. No Starch Press, 2024. Bash automation for red teams, living-off-the-land attacks, and offensive tooling.
nostarch.com/black-hat-bashAwesome Drone Hacking
Curated resource collection: tools, references, simulators, and reading for drone offensive security practitioners.
github.com/nicholasaleks/Awesome-Drone-HackingFOUNDED BY
HACKERS.
// CHIEF HACKING OFFICER · NICK ALEKS
Co-author of Black Hat GraphQL (2023) and Black Hat Bash (2024). Founder of DEFCON Toronto (DC416), Canada’s largest hacker community, ten years running in 2026. Over a decade protecting Canada’s largest financial institutions: TD Bank, Wealthsimple, Robinhood.
Hacks websites, safes, locks, cars, drones, and intelligent buildings, and built the open-source Damn Vulnerable Drone that the industry trains on.
- DC416 Founder · 2016
- Author · Black Hat GraphQL (2023)
- Author · Black Hat Bash (2024)
- Damn Vulnerable Drone · 402 ★
- CrackQL · 346 ★
- GraphQL Threat Matrix · 361 ★
- Patented Security Engineer
- MapleSEC 2022 · Keynote
- GraphQL Summit 2022
- CanSecWest 2024 · DOJO
- Drone Talk · US 2025
- U of Guelph · M.Cyber Advisory
- George Brown · Advisory
- HackStudent · Senior Advisor
Canadian industry
bodies.ASEC operates inside the four industry bodies that credentialize federal-defence procurement, sovereign-Canadian defence, threat-intelligence sharing, and the national cyber cluster.
- M-01CADSICanadian Association of Defence and Security Industries
Federal defence procurement signal - M-02ACDCAlliance of Canadian Defence Companies
Sovereign-Canadian defence collective - M-03CCTXCanadian Cyber Threat Exchange
Threat-intel community, Big Six banks and telcos - M-04IN-SEC-MCanadian Cybersecurity Cluster
National cyber industry cluster
Engagements / Selected
Full-scope offensive engagements across building-automation, crypto-finance, GraphQL APIs, and mobile platforms. Paragraph case studies in lieu of a logo wall; named with client approval only.
Tridel
Full-scope offensive security assessments of Toronto Smart Condos: physical, wireless, network, mobile, web, cloud, and IoT. Adversarial testing across building automation systems at scale.
Integral
Fortify Crypto Financial Operations with continuous assessments. Part of Integral's SOC 2 journey. Full-scope assessment of the cloud-based financial platform plus ongoing engagement.
Pearler
GraphQL API and mobile-application security testing. iOS and Android assessment plus deep GraphQL adversarial review by the authors of Black Hat GraphQL.
TriplePlay
Targeted assessment engagement, scope and findings under NDA. Representative of ASEC private-engagement work for technology and media-platform clients.