assis@brutelogic.net:~$ whoami

Brute Logic
data as instruction, and where it breaks.

Rodolfo Assis, Brazilian offensive security researcher. 15+ years finding the exact failure mode where a boundary the system promised to enforce collapses — from SQL injection and XSS to prompt injection. Creator of KNOXSS. Four things live here: the research, the ebooks, the doctrine, and the current writing.

1,000+
Vulnerabilities disclosed
15+ yrs
XSS & web security
2016–2026
KNOXSS, 10-year run
DEF CON
Ekoparty · BSides
// Start here
01
2014 — 2024 · Primary source record

Research

61 posts documenting the original work: Multi-Reflection XSS, Quoteless Injection, the 7 Main XSS Cases, Agnostic Event Handlers. The foundation everything else here is built on.

Read the record
02
PDF · Lifetime updates

Ebooks

First Bounty, SSRF Mastery, The Brute Art of Bypass, Broken Token, AfterMath — practical, field-tested guides for bug bounty hunters, written from inside the practice.

Browse the collection
03
Free · Work in progress

Security in Collapse

A cyberpunk doctrine for the Intelligence Age. Data misclassified as instruction — the primitive behind every injection vulnerability in history — now migrating into probabilistic AI systems.

Read the doctrine
04
Investigative writing

Charted Territory

Analytical writing on AI, cybersecurity, and the intelligence age. Claims checked against primary sources — no press releases paraphrased.

Start reading
// Testbeds

Built for KNOXSS, the King of Noobs suite, and the Broken Token tools — but generic enough to point any tool or setup at.

King of Noobs suite on GitHub — reKover · unKover
Rodolfo Assis@brutelogic · Brazil
KNOXSS — automated XSS detection, live since 2016 X55.is — universal XSS delivery domain Top 200 Global Cybersecurity Influencer, 2021 DEF CON 24/25 · Ekoparty · BSides Boston