Application Security · Vulnerability Research · Security Tooling

Signal what matters.
Ignore the rest.

Practical research on how software breaks—and how to build it safer.

By Paolo Perego, Product Security Engineer and open-source security tooling builder.

Featured

I Was Never Trying to Build Just Another SAST

OWASP Orizon started in 2006 with ASTs, program models, call graphs and data flow. Dawnscanner took a more pragmatic path. Twenty years later, DRSource is bringing me back to the same question: how much of a program must an analysis engine understand to become...

Read insight

Editorial focus

Where software and security meet

Security Research

Deep analysis of vulnerabilities, exploitability and real attack surfaces.

Explore this area

Secure Software Engineering

Code review, threat modeling, secure design and practical engineering guardrails.

Explore this area

Security Tooling

Open-source tools that reduce noise and turn findings into actionable signal.

Explore this area

Python · security findings analysis

Signal Engine

Normalizes, deduplicates, clusters, and scores findings from multiple security tools to surface actionable risk.

View project

Source-code security scanner

dr_source

An open-source security code review engine exploring cross-file data flow, program modelling and explainable attack paths.

View project

Python · web application testing

Nightcrawler-mitm

A mitmproxy-based research tool for scoped crawling, passive analysis, and focused active security checks.

View project

Ruby · static analysis

Dawnscanner

A source-code security scanner for Ruby web applications, with checks for vulnerable dependencies and unsafe code patterns.

View project

About the author

Security work grounded in engineering.

Paolo Perego works at the intersection of software engineering and security. He reviews code, researches vulnerabilities and builds open-source tools that help engineering teams separate meaningful risk from security noise.