Red Dragon Security
Specialist lab and consultancy delivering private threat intelligence, exploit research, tooling, and AI‑driven cyber research. We combine OSINT, OPSEC, and advanced analytics to produce actionable intelligence for selective clients.
Services
Private Threat Intelligence
Tailored intelligence for executive teams and security operations. Dark web monitoring, actor profiling, infrastructure mapping, and bespoke intelligence briefs delivered under NDA.
Exploit Research
Responsible discovery and analysis of vulnerabilities. We provide safe, non‑destructive proof summaries, exploitability assessments, and coordinated disclosure support.
Tool Development
Custom tooling for secure operations, automation, and research workflows. Focus on reproducible, auditable tools with clear OPSEC controls.
AI for Cyber Research
Applying LLMs and graph AI to threat hunting, triage, and enrichment. Pipelines prioritise safety, redaction, and human‑in‑the‑loop review.
OPSEC & OSINT Research
Operational security reviews, adversary emulation planning, and advanced OSINT collection strategies that respect legal and ethical boundaries.
Consultancy
Advisory services for boards, incident response teams, and product security groups. Short engagements, retainers, and long‑term strategic partnerships available.
Research
Active Research Streams
- Private TI — actor profiling, infrastructure mapping, targeted monitoring.
- Exploit lifecycle — safe analysis, reproducible writeups, disclosure playbooks.
- AI for security — applied research into model‑assisted triage and safe automation.
Research Outputs
Non‑sensitive summaries and safe writeups of research outputs are published here when appropriate. Private reports and detailed technical briefs are available under NDA.
Responsible Practices
All research follows strict legal review, OPSEC controls, and human‑in‑the‑loop validation. We do not publish exploit code or enable unsafe replication.
Active Projects
Current engineering and research efforts. All projects follow strict OPSEC, legal review, and human‑in‑the‑loop controls.
MFA Proxy Attack Detection
Developing detection techniques and telemetry for proxy‑based MFA bypass attempts, focusing on behavioural signals, session anomalies, and automated alerting for SOCs.
Intelligent Blind Fuzzing
Building a fuzzing framework that uses adaptive heuristics and lightweight ML to prioritise inputs, reduce noise, and find edge‑case crashes in large codebases without heavy compute.
AI Cognitive Attacks
Research into adversarial and social engineering vectors amplified by generative models, with a focus on detection, mitigation, and policy guidance for defenders.
Pentesting AI Agents
Evaluating autonomous pentest agents and red‑team bots to understand their capabilities, failure modes, and safe containment strategies for responsible use in engagements.
Darknet Research for Threat Intelligence
Targeted collection and analysis of darknet marketplaces and actor infrastructure to enrich private TI feeds, prioritising legal compliance and non‑intrusive collection methods.
Tools
Consulting
Engagement Models
Short advisory calls, scoped research engagements, and retained intelligence services. Pricing and NDAs provided after an initial scoping call.
How to Engage
Use the contact form below or email matthew@business-analytica. For UKCybersecurity referrals, follow the link in the header to our consultant profile.
History
Red Dragon Security is a specialist practice led by Matthew Beddoes. The practice combines OSINT, cyber research, and systems architecture experience to deliver high‑value intelligence and tooling for clients across government, enterprise, and critical infrastructure sectors.
Press & Mentions
Featured on BBC Radio 2, BBC Radio Merseyside, and LBC Radio as a cyber security consultant.