01Explore Map the attack surface
Azimuth crawls the codebase, dependencies, contracts, privileged functions and system interactions to understand how the protocol behaves and where value can move.
- contracts/
- dependencies/
- privileged functions
- token flows
- external integrations
02Hypothesize Think like an attacker
Azimuth generates potential exploit paths across the system, including vulnerabilities that emerge through combinations of contracts, permissions, transactions and state changes.
- Cross-contract drain
- Oracle manipulation
- Access control bypass
- Privilege escalation
- Governance takeover
03Execute Prove it against real state
Azimuth forks mainnet state and executes the proposed attack path, manipulating state and chaining transactions to determine whether the vulnerability can actually be exploited.
$ fork --block 19,482,221$ deploy exploit contract$ execute attack path$ track state changes✓ Execution successful
04Confirm See exactly where it breaks
Successful attacks become confirmed findings, giving you the vulnerable path, execution trace and a working proof-of-concept.
! CriticalCross-contract drain
- Attack path
- Execution trace
- Proof-of-concept
- Reproduction steps
- Recommended fix