Register-file forensics
Zenbleed-class bugs leak vector registers across SMT siblings. We prove whether your Zen 2/3 hosts still have a window, even when the vendor advisory says “fixed.”
Agent scanners never look at the die. Zenbleed maps every host in your fleet to speculative-execution leaks — register files, gather buffers, stale microcode — and tells you which silicon is still lying to the OS.
Powered by CPUID · microcode · KVM
Patch Tuesday says you are fine. The register file disagrees. We fingerprint the actual CPU, the microcode blob, and the hypervisor mitigations — not the package changelog.
Zenbleed-class bugs leak vector registers across SMT siblings. We prove whether your Zen 2/3 hosts still have a window, even when the vendor advisory says “fixed.”
Cloud images freeze microcode. We diff every instance against the latest Intel/AMD blobs and flag hosts whose virt-firmware never applied the silicon patch.
KVM, Xen, and the big three clouds each advertise different SPECTRE flags. We reconcile /proc/cpuinfo, CPUID leaves, and guest-visible MSR policy into one score.
Each scan scores every host against the bleeds we actually see in production. Click a family when the report lands — the CLI already names them.
Register file bleed
Zenbleed
Gather data sampling
Downfall
Nested prediction
Inception
Speculative store
bypass
Rogue data cache
Meltdown-class
Return stack buffer
Retbleed
Guest/host split
GhostRace
Uncached microcode
drift
A 4 MB static binary. It reads CPUID, microcode revision, and hypervisor mitigation bits. It never issues a speculative attack primitive. Reports are SARIF, JSON, or a page your CISO can open.
Deterministic. Diffable. Safe to run on production hypervisors.
Beta is invite-only. We onboard one cloud account at a time, sign a narrow IAM role, and return a fleet bleed report in under an hour.
First 50 orgs. No credit card. We scan a slice of prod and send the SARIF.
We only email about the beta. No exploit samples, no marketing blasts.
Issued after a clean ZB-01…ZB-08 pass on a production fleet
A signed attestation over CPUID, microcode revs, and hypervisor flags — not a PDF checkbox from last year’s pentest.
Finding a bleed is half the job. We train the people who own the images so the next errata does not sit unpatched for nine months.
When a new CPU advisory drops, we replay it against your last scan and tell you which images, instance types, and regions are exposed before the vendor blog finishes loading.
Each finding ships with the exact microcode package, kernel cmdline, and hypervisor flag to flip — mapped to Ubuntu, RHEL, Bottlerocket, and the major cloud images.