Bloodhound
Grey-box attack-path discovery in Rust/Go/C++ binaries
Details
- External ID
- 46210748
- Source
- HN
- Company
- —
- Product
- Bloodhound
- Website domain
- bloodhoundsecurity.ca
- Launched
- Dec. 9, 2025
- Cohort
- —
- Upvotes
- 5
- Upvotes percentile
- 0.10400763358778627
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:25 p.m.
- Updated at
- Sept. 7, 2026, 9:25 p.m.
Description
We originally set out to solve complex debugging headaches and useless alerts caused by traditional security scanners in our own projects. Static Analysis (SAST) flagged too much noise because it couldn't verify runtime context, while Dynamic Analysis (DAST) missed internal logic bugs because it treated the app like a black box.We built a CLI tool to bridge this gap using grey box testing from a red team approach. We use internal knowledge of the codebase to guide parallel execution, allowing us to find complex or hidden logic errors and attack paths standard linters/scanners miss.The Tech (Grey Box Graphing & Execution): - Internal Graphing (The Map): It ingests the codebase to build a dependency graph of the internal logic. - Parallel Execution (The Test): The code is then tested on parallel engines. We spin up copies of your local dev environment to exercise the codebase in thousands of ways. This is the validation that proves a bug is real. - Logic Error Detection: Because It understands the intended architecture (the graph) and sees the actual behavior (execution), we can flag Logic Errors, (ex. race conditions, state inconsistencies, memory leaks etc). - Tainted Flow Mapping: We map tainted control flow over the dependency graph. This highlights exactly how external input threads through your logic to trigger a vulnerability. It then spins up a local instance to replay this flow and confirm the exploit.How it runs: It runs locally via CLI to maintain privacy with secure repos and ease. Generates remediation via MD reports pinpointing the line of the error and downstream effects.The Trade-off: This approach trades power for speed and deep testing. This testing engine is recommended for more sophisticated systems.Try it out: We are currently opening our beta VS extension for early users.Optimized for (Rust, C++, Go, Java) and IaC (Terraform, Docker, K8s). Also supports Python, TS/JS, C#, PHP, and (20+ other languages).P.S. We are happy to run this ourselves on repos. If you maintain a complex project and want to see if our engine can find logic or security holes, drop a link or reach out via the comments/site and we’ll do it and send the results.
Enrichment
- Theme
- security exploits and system hacking tools
- Vertical
- Security
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- attack path discovery in binaries
- Manually corrected
- False
Could you build this?
No Grey-box attack-path discovery in compiled binaries (Rust/Go/C++) requires deep reverse engineering, binary intermediate representation (IR) lifting, symbolic execution, and vulnerability research that AI coding assistants cannot independently formulate.
What it would actually take: A real implementation relies on binary disassembly and decompilation frameworks (like LLVM, Ghidra, or Binary Ninja), lifting machine code into an intermediate representation to perform inter-procedural taint analysis, control-flow graph (CFG) recovery, and directed grey-box fuzzing (e.g., AFL++ or custom symbolic execution engines like angr). The hardest part is accurately reconstructing memory layouts and control flow in optimized, stripped binaries without source code, accounting for runtime environments like Go's runtime scheduler or Rust's monomorphization. This requires elite offensive security researchers and compiler engineers.
Discussion
8 comments analyzed.
Competitors mentioned: BloodHound (existing security tool), Mend/WhiteSource, CodeQL, SCA tools
Concerns raised: Name conflicts with established BloodHound security tool, potential legal issues, Perceived as LLM wrapper without significant engineering, High pricing ($2K per run), Unclear differentiation from existing tools like CodeQL and Mend
Feature requests: IDE/VS Code extension with inline code highlighting and execution flow tracing, Auto-generate and validate exploits for vulnerabilities
Competitors
Other products that read as similar to this one — 248 launches clear the similarity bar, closest 8 shown.
Attention rank: #226 of 249 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 39 days after the earliest competitor.
- Sighthound · hn · 2026-07-09 · 19 upvotes · similarity 0.46
- CodeDiff · hn · 2026-09-29 · 6 upvotes · similarity 0.45
- Shrouded, secure memory management in Rust · hn · 2026-03-23 · 5 upvotes · similarity 0.45
- CodeDrift · hn · 2026-03-05 · 5 upvotes · similarity 0.44
- I made an open-source Rust program for memory-efficient genomics · hn · 2025-11-13 · 17 upvotes · similarity 0.44
- Tangent · hn · 2025-11-20 · 28 upvotes · similarity 0.43
- Valdr · hn · 2026-06-01 · 5 upvotes · similarity 0.43
- Sandboxing untrusted code using WebAssembly · hn · 2026-02-03 · 76 upvotes · similarity 0.42
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.