凌曦安全

LingXi Security Team

Security Research · Adversarial Practice

Research. Defend. Advance.

About Us

Founded in 2023, LingXi Security focuses on vulnerability research, red and blue team operations, cloud security, JavaScript reverse engineering and endpoint defense. Our members come from leading security vendors, technology companies, universities and the independent research community.

Vulnerability Research

Focused research across major vendor security response platforms, backed by consistent, high-quality findings.

Red & Blue Teaming

Hands-on adversarial operations and defense experience across realistic enterprise environments.

Technical Community

An open, practical community that connects security practitioners and independent researchers.

Team Members

Security practitioners working across complementary disciplines

Syst1m

Syst1m

Team Lead

Security operations, adversarial testing and incident response.

八幡.

八幡.

Binary Security

Security tooling and binary research.

浪🌊

浪🌊

Web Security

Web security research

江海

江海

Web Security

Web security research

KeyL

KeyL

Web Security

Web security research

MaAp1e

MaAp1e

Web Security

Web security research

吃不饱の崽

吃不饱の崽

Web Security

Vulnerability research

Juzi

Juzi

Code Audit

Secure code review

Research Articles

Security research and technical field notes from the team

Cloud Security
2026-01-02

Kubernetes Lateral Movement Research (Part I)

An analysis of exposed etcd services, Kubernetes secrets and attack paths that can lead from cluster access to node compromise.

Read article
Social Engineering
2026-01-09

File Disguise Techniques in Phishing Scenarios

A practical review of icon replacement, filename confusion, RLO characters, shortcuts and self-extracting archives, with defensive guidance.

Read article
Social Engineering
2026-01-08

Anatomy of an Email Phishing Operation

A technical walkthrough of phishing infrastructure, delivery workflows, common controls and defensive detection opportunities.

Read article
Reverse Engineering
2025-9-11

JavaScript Reverse Engineering from Zero to One

A hands-on introduction to locating and analyzing browser-side cryptography and application logic through real cases.

Read article
Penetration Testing
2025-7-14

From a Mini App to vCenter: Attack Chain Review

A complete review of an authorized security assessment that moved from an external mini app to a virtualized internal environment.

Read article
Incident Response
2025-3-28

Cryptominer Incident Response in Practice

A field report covering alert triage, threat intelligence, endpoint investigation and malicious process analysis.

Read article

Team Honors

Consistent results built through practical security research

2025

迅雷SRC

Annual rank #1

2025

360SRC

Annual rank #3

2025

EDUSRC

Annual rank #7

2024

360SRC

Annual rank #3

2023

360SRC

Annual rank #3

More achievements will be added over time...

Contact Us

Get in touch for security research, responsible disclosure and technical collaboration.