Skip to content
Talk to a Security Expert
// TMG SECURITY RESEARCH

Research what attackers see.
Build what defenders need.

Security research should go beyond theory. TMG Security develops practical research environments, vulnerable applications and security labs designed to help security professionals explore modern attack surfaces in controlled environments.

LABSLABS
VULNERABLE APPLICATIONSVULN. APPS
APIsAPIs
AI SECURITYAI
ATTACK SURFACESSURFACES
SECURITY TELEMETRYTELEMETRY
RESEARCHRESEARCH
TMG RESEARCHSECURITY LABS

CONCEPTUAL DIAGRAM · ILLUSTRATIVE, NOT LIVE DATA

// PRACTICAL SECURITY RESEARCH

Learn security by breaking realistic systems.

TMG Security Labs are designed as controlled environments for security testing, vulnerability research and practical learning. Each lab focuses on a different attack surface and is designed to help researchers understand how vulnerabilities appear, how they can be investigated and how secure implementations should behave.

AVAILABLE FOR ACCESSAI / LLM SECURITY

TMG AI Security Lab

For Penetration Testers & Security Researchers

A practical environment focused on exploring security weaknesses across modern AI and LLM-powered systems. Described in the project as a locally-runnable, intentionally vulnerable AI / LLM / agentic security training environment, built as a hands-on companion to TMG Security's AI / LLM Penetration Testing & Bug Bounty course.

IMPLEMENTED COVERAGE

  • OWASP LLM Top 10 (2025) — all ten
  • OWASP Agentic AI ASI01–ASI10 — all ten
  • Prompt injection
  • System prompt leakage
  • Sensitive information disclosure
  • Data & model poisoning
  • Vector & embedding weaknesses
  • Improper output handling
  • Unbounded consumption
  • Misinformation
  • Excessive agency
  • Agent goal hijacking
  • Tool misuse
  • Identity & privilege abuse
  • Memory & context poisoning
  • Agentic supply chain
  • Unexpected code execution
  • Insecure inter-agent communication
  • Cascading failures
  • Human-agent trust exploitation
  • Rogue agents

Also includes Bug Bounty Mode (an unguided target with no hints or category labels), a structured vulnerability reporting module, a local leaderboard and an instructor mode.

LEVELS
20 (L01–L20)
MODE
Guided + Bug Bounty
RUNTIME
Docker, fully offline
AI KEY
Not required
ACCESS THE LAB
IN DEVELOPMENTWEB APPLICATION SECURITY

TMG Vulnerable Web Application Lab

For Web Pentesters & Bug Bounty Researchers

A controlled vulnerable web application environment designed for practical web application security testing and vulnerability research, focused on realistic web application attack surfaces.

The vulnerability coverage for this environment has not been finalised, so none is listed here. It will be published once the lab is built.

STATUS
In development
SCOPE
Being defined
ACCESS
Not yet available
TARGET
Web application
REGISTER INTEREST
IN DEVELOPMENTAPI SECURITY

TMG Vulnerable API Lab

For API Security Testers

A controlled environment designed to help security professionals explore API security weaknesses and understand how modern APIs can become part of an organization's attack surface.

The vulnerability coverage for this environment has not been finalised, so none is listed here. It will be published once the lab is built.

STATUS
In development
SCOPE
Being defined
ACCESS
Not yet available
TARGET
API surface
REGISTER INTEREST
IN DEVELOPMENTAPPLICATION SECURITY

TMG Application Security Lab

For Security Engineers & Researchers

A practical application-security environment focused on understanding vulnerabilities across modern application workflows, integrations and security controls.

The vulnerability coverage for this environment has not been finalised, so none is listed here. It will be published once the lab is built.

STATUS
In development
SCOPE
Being defined
ACCESS
Not yet available
TARGET
Application workflows
REGISTER INTEREST

ONE LAB IS BUILT AND RUNNING · THE OTHER THREE ARE IN DEVELOPMENT AND THEIR SCOPE IS NOT YET PUBLISHED · STATUS ON EACH CARD IS ACCURATE

// ATTACK SURFACES

Explore the surfaces attackers look for.

Select a surface to see which lab environment covers it. Surfaces without a lab yet are shown as such rather than mapped to something that does not exist.

ATTACK SURFACE
RESEARCH

Every lab starts from research into how a surface is actually attacked, and ends in an environment where that behaviour can be reproduced safely.

WEB
TMG Vulnerable Web Application LabIN DEVELOPMENT
API
TMG Vulnerable API LabIN DEVELOPMENT
AI
TMG AI Security LabAVAILABLE FOR ACCESS
APPLICATION
TMG Application Security LabIN DEVELOPMENT

IDENTITY, CLOUD and DATA are surfaces TMG Security works across in its services practices. They do not have a dedicated lab environment yet.

// WHY SECURITY LABS

Realistic environments. Controlled research.

01

PRACTICAL

Learn through realistic environments rather than theory alone.

02

CONTROLLED

Explore vulnerabilities within intentionally designed environments.

03

RESEARCH-DRIVEN

Labs evolve around modern security problems and attack surfaces.

04

DEFENSIVE CONTEXT

Understand not only how vulnerabilities occur, but why secure design matters.

// RESEARCH WORKFLOW

How a weakness becomes understanding.

The same five steps whether the surface is a web application, an API or an AI agent.

01

IDENTIFY

Research an attack surface.

02

REPRODUCE

Investigate the behavior in a controlled lab.

03

UNDERSTAND

Analyze why the weakness exists.

04

VALIDATE

Understand the security impact.

05

REMEDIATE

Study the secure design or defensive control.

// RESEARCH ENVIRONMENT

What starting a lab session looks like.

An illustration of the sequence a research environment goes through as it comes up: initializing the environment, loading lab definitions, mapping the attack surface, analyzing application behavior, evaluating security controls, ready. The panel below is scripted for this page — it is not connected to a running system.

TMG SECURITY RESEARCH TERMINAL ILLUSTRATIVE UI
SCRIPTED SEQUENCE FOR ILLUSTRATION · NOT LIVE OUTPUT · NOT CONNECTED TO ANY SYSTEM
// RESEARCH BEYOND LABS

The formats research gets published in.

These are the formats TMG Security research will be published in. Nothing has been published yet, so nothing is listed — the cards below describe the format, not an article.

RESEARCH REPORT

Research Report

Long-form research write-ups on attack surfaces TMG Security works across.

COMING SOON
SECURITY ADVISORY

Security Advisory

Structured advisories covering issues found during research work.

COMING SOON
TECHNICAL BLOG

Technical Blog

Shorter technical pieces on tooling, methodology and modern attack surfaces.

COMING SOON
VULNERABILITY RESEARCH

Vulnerability Research

Deeper vulnerability research from the labs and from client-facing work.

COMING SOON
// SECURITY RESEARCH ARCHIVE

The archive is ready. The shelves are not full yet.

Filtering works. There is simply nothing published to filter — and we would rather show you that honestly than fill the page with placeholder articles.

NO PUBLICATIONS YET

There is no published research in ALL yet. TMG Security research is in progress; this archive will fill as reports, advisories and technical write-ups are released.

// LAB ACCESS

Want access to a TMG Security Lab?

Our labs are designed for controlled security research and practical learning. Tell us which environment you're interested in and the TMG Security team can help with access and next steps.

Research is where the next engagement starts.

Whether you want lab access, want to talk about a surface we have been researching, or need the same thinking applied to your own environment — start with the problem.