Skip to content

Security: K4N3CO-LABS/Lab-RATS

SECURITY.md

ic-launcher-playstore.png

Lab-RATS: Security & Vulnerability Policy

Operational Security (OpSec) is our highest priority. If you find a hole in the Lab-RATS engine or a way to compromise the C2 protocol, we expect you to handle it like a professional.

0x01: Responsible Disclosure

Do NOT open public issues for security vulnerabilities. Leaking a bypass or a protocol flaw before it's patched compromises the entire lab.

Report vulnerabilities via the following channels:

  • Encrypted Comms: K4N3CO.LABS@proton.me
  • Target Response: We aim to acknowledge reports within 48 hours and have a patch in the pipeline shortly after.

0x02: Scope

We are primarily interested in:

  • Protocol Breaches: Ways to hijack the C2 handshake or intercept telemetry.
  • De-cloaking: Methods that allow a target OS to permanently flag or unmask the app despite stealth mode.
  • Sandbox Escapes: Flaws in the Ghost Controller or Accessibility logic that lead to system crashes.

0x03: The Reward

Your name in the CONTRIBUTORS.md and the respect of the lab. We value those who build shields as much as those who build spears.


Keep the signal high. Maintain OpSec.

There aren't any published security advisories