Zenbleed
Stealth Beta Access

Hunt every
CPU bleed

Agent scanners never look at the die. Zenbleed maps every host in your fleet to speculative-execution leaks — register files, gather buffers, stale microcode — and tells you which silicon is still lying to the OS.

Powered by CPUID · microcode · KVM

Silicon we already fingerprint
AMD ZEN INTEL ARM KVM
zenbleed — prod-fleet
~ $ zenbleed scan --fleet prod
[+] enumerating 1,248 vCPUs across 3 regions
[+] CPUID: AuthenticAMD family 19h model 01h (Zen 2)
[!] ZB-01 register-file leak — microcode 0x0830107a stale
[+] Downfall (CVE-2022-40982) mitigated on 1,102 hosts
[!] 146 hosts still expose gather-data sampling
[+] signed SARIF written to ./zenbleed/report.sarif
Auto-detects CPUID · Maps errata to live hosts · Exits 1 on unmitigated bleed

The silicon: beyond CVE scanners

Patch Tuesday says you are fine. The register file disagrees. We fingerprint the actual CPU, the microcode blob, and the hypervisor mitigations — not the package changelog.

Register-file forensics

Zenbleed-class bugs leak vector registers across SMT siblings. We prove whether your Zen 2/3 hosts still have a window, even when the vendor advisory says “fixed.”

Fleet microcode drift

Cloud images freeze microcode. We diff every instance against the latest Intel/AMD blobs and flag hosts whose virt-firmware never applied the silicon patch.

Hypervisor truth table

KVM, Xen, and the big three clouds each advertise different SPECTRE flags. We reconcile /proc/cpuinfo, CPUID leaves, and guest-visible MSR policy into one score.

The eight ways silicon fails

Each scan scores every host against the bleeds we actually see in production. Click a family when the report lands — the CLI already names them.

ZB-01

Register file bleed
Zenbleed

ZB-02

Gather data sampling
Downfall

ZB-03

Nested prediction
Inception

ZB-04

Speculative store
bypass

ZB-05

Rogue data cache
Meltdown-class

ZB-06

Return stack buffer
Retbleed

ZB-07

Guest/host split
GhostRace

ZB-08

Uncached microcode
drift

Zero kernel module. Zero exploit payload.

One agent.
Read-only silicon.

A 4 MB static binary. It reads CPUID, microcode revision, and hypervisor mitigation bits. It never issues a speculative attack primitive. Reports are SARIF, JSON, or a page your CISO can open.

zenbleed report — last 24h
Hosts scanned1,248
Unmitigated ZB-0137
Stale microcode146
Clean silicon1,065

Deterministic. Diffable. Safe to run on production hypervisors.

Secure waitlist

Start with verified silicon

Beta is invite-only. We onboard one cloud account at a time, sign a narrow IAM role, and return a fleet bleed report in under an hour.

Founding fleet

Early access

First 50 orgs. No credit card. We scan a slice of prod and send the SARIF.

$0 / beta

We only email about the beta. No exploit samples, no marketing blasts.

Silicon Attested

Issued after a clean ZB-01…ZB-08 pass on a production fleet

A signed attestation over CPUID, microcode revs, and hypervisor flags — not a PDF checkbox from last year’s pentest.

Continuous silicon literacy

Finding a bleed is half the job. We train the people who own the images so the next errata does not sit unpatched for nine months.

Errata war-room

When a new CPU advisory drops, we replay it against your last scan and tell you which images, instance types, and regions are exposed before the vendor blog finishes loading.

Owner playbooks

Each finding ships with the exact microcode package, kernel cmdline, and hypervisor flag to flip — mapped to Ubuntu, RHEL, Bottlerocket, and the major cloud images.