Founder
Erez Metula
engineer, author, founder
Founded AppSec Labs in 2010, the same year Syngress published his book on attacking managed runtimes. He has spent the two decades since doing one thing: understanding how software is built, in order to attack it.
2009-2010
How a conference talk became a book, and a company
The company and the book have the same origin, in the same year, and the order matters.
In 2009 he presented managed code rootkits - attacks that live inside the runtime itself, beneath the application - at Black Hat USA and DEF CON. A commissioning editor at Syngress was in the audience. The book that followed took the next year to write, and writing it meant leaving the application security department he was running to do it properly.
AppSec Labs and Managed Code Rootkits were both born in 2010. That is not a coincidence in the company’s history; it is the company’s thesis. Attacking a runtime requires reading it like an engineer first. So does attacking an application.
On the record
Published, taught, archived
Three things a buyer can verify without asking us.
Managed Code Rootkits
Hooking into Runtime Environments
Syngress (Elsevier), 2010 · ISBN 978-1-59749-574-5
The first full-length treatment of attacks against the .NET CLR, the JVM and Dalvik - the layer beneath the application, where a compromised runtime can lie to every program above it.
Its technical editor was Michael Howard, author of Writing Secure Code and one of the architects of Microsoft’s Security Development Lifecycle - a reviewer whose work Erez had been reading for years before the publisher put them on the same manuscript.
Black Hat USA, 2013-2017
For five consecutive years he taught Android Application Hacking at Black Hat USA, plus Black Hat Asia - the course that took developers and testers through reversing, instrumenting and breaking real mobile applications.
Every one of those years is listed in Black Hat’s own public archive, which is the point: it is checkable without taking our word for it.
Today
Sixteen years on
What he does now
Runs AppSec Labs, which does one thing: penetration testing of software-based systems - web applications, APIs, mobile apps, and the AI features increasingly built into them.
Where the platform came from
CybeRapid, the testing platform our engineers work on, is ours and still developed today. It runs breadth so the humans can spend their hours on authorization, tenant isolation and business logic - the flaws that require understanding a system.
Still writing
He publishes near-daily analysis of application and AI security - incidents, techniques, and what we keep finding in real engagements. Much of it ends up here as research.
2010-2018, discontinued
The teaching years, and why they still matter to a report
Between 2010 and 2018 AppSec Labs also ran a substantial secure-coding and application-hacking training practice - around 500 sessions worldwide, roughly 5,000 developers. That practice was discontinued in 2018 and is not offered.
It is worth a paragraph here for one reason. Teaching 5,000 developers how their own code gets broken is why our findings are written the way they are: for the engineer who has to fix the thing, with reproduction steps and a concrete remediation, rather than for the person filing the report.
Want to talk to him?
Erez still scopes engagements personally where it matters. A call is the fastest way to find out whether we are the right team for what you have built.