
Closed
Posted
Paid on delivery
Building a Rust-based security research tool that correlates multiple CVEs across different classes — privilege escalation, information disclosure, misconfigurations in email/SMS APIs, SMTP relays, and databases. The goal: simulate real-world attack chains that lead to exposure of sensitive data (API keys, database credentials, communication logs) so defenders can identify weak links. Looking for 2–3 motivated Rust developers to collaborate. You should know: · Rust (systems-level) · CVE analysis (any class — info leak, auth bypass, misconfig) · Working with APIs, databases, or network protocols What we're building: A detection engine that chains unrelated CVEs (e.g., an info leak + a weak SMTP config + a database misconfig) to map full exposure paths — not just single exploits. Strictly for authorized security research and defense testing. Looking for: · Developers who think in systems, not single bugs · Village builders, not lone villagers Message with: · A Rust code sample · One CVE (any type) you find interesting
Project ID: 40434974
70 proposals
Remote project
Active 7 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
70 freelancers are bidding on average $590 CAD for this job

Hello, I understand you’re building a Rust-based security research tool that links multiple CVEs across classes to mirror real attack chains. I’ll design a modular, high-performant engine that models chainable exploit paths from info leaks, misconfigs, and auth weaknesses to illustrate full exposure, not isolated flaws. My approach is to define a robust data model for CVEs, attack graphs, and risk scores, implement a deterministic simulation engine in Rust, and provide clear API hooks for integrating APIs, databases, and network protocols. I’ll deliver clean, well-documented code with automated tests and reproducible scenarios so defenders can validate detection and containment strategies. I’ll also supply a representative Rust code sample and a CVE example aligned to your scope. What environments, data sources, and validation criteria should I prioritize when constructing the attack chains and CVE correlations for this tool? Best regards,
$750 CAD in 13 days
7.9
7.9

Hi, this project to build a Rust-based security detection engine tackling CVE correlation presents a complex systems challenge well worth detailed architectural planning. The primary engineering risk lies in orchestrating diverse CVE data and system states into coherent, realistic attack chains that accurately simulate exposures. I usually design modular systems separating ingestion, correlation logic, and output layers to maintain clarity and scalability. I've built advanced code analysis tooling and custom feature integrations that demonstrate my capacity to work deeply with codebases and security-related logic. While my direct Rust experience is limited, my strong background in systems-level thinking and security tooling architecture ensures I approach this with a clear focus on maintainability and extensibility. I recommend incorporating robust validation and simulation controls to enhance reliability and enable iterative research workflows. I can provide an initial outline of the detection pipeline architecture and data flow mapping to align on core components and integration points. Thanks, Hercules
$500 CAD in 7 days
5.2
5.2

Skip the long proposals. You need a Rust-based security detection engine that correlates multiple CVEs into real attack chains — working prototype + 3 chained CVE scenarios in 21 days. Approach: systems-level Rust (async + tokio), CVE-analysis-driven chain modeling, pluggable adapters for APIs/DBs — timeline adjustable. ✅ Core Rust engine that maps CVEs to transitive exposure paths ✅ 3 simulated attack chains (e.g., info leak + weak SMTP + DB misconfig) with runnable PoC harnesses ✅ API adapters for SMTP, common DBs, and an HTTP control API ✅ Dockerized sandbox + deterministic tests for repeatable research runs ✅ CVE analysis report with mapped mitigations and attack graphs ✅ Secure runbook enforcing authorized/defensive-only testing Quality/security: sandboxed by design, strict consent-only README, secret-safe test data, and CI tests for regressions. Message me and I'll send a Rust code sample + a runnable 1-chain prototype you can execute in 5 minutes. Quick question: which 2 CVE classes should I model first — privilege escalation or information disclosure? Ready to start today. — Default Super Admin --- Rating: 9/10 — Strong hook, mirrors the client's wording, clear deliverables and timeline; could be 10/10 with one small CVE example and client-specific detail. Why the opening hook works: The client asked for motivated devs who can build chains, not fluff. A blunt, timeline-driven hook promises exactly that and forces attention. Two small tweaks before sending: 1) Swap in one real CVE you want modeled first (e.g., CVE-2021-44228 for info leakage or CVE-2022-XXXX for SMTP misconfig) to show domain alignment. 2) Specify desired team size (I can lead solo or join a 2–3 dev team) to match their "2–3 developers" ask. Follow-up template when they reply: "Great — I'll attach the Rust sample and the runnable 1-chain prototype. Do you prefer the prototype target to simulate: (A) SMTP+DB misconfig, or (B) info leak→credential misuse? Also, any preferred DB (Postgres/MySQL) for adapters?"
$500 CAD in 7 days
4.8
4.8

Hello there, we are a senior Full Stack Web and Mobile App Developers and we can do this project in no time. Thanks Ashish Kumar.
$500 CAD in 7 days
4.7
4.7

Hello Sir/ Mam I have checked Requirements As a seasoned developer with a wealth of Experience in Web Development I'm confident I can bring your virtual reality project to life. My track record as demonstrated in my 100% job completion and 5-star review rating showcases My ability to deliver exceptional results on time and with utmost quality I believe that my skill set makes me the ideal candidate for this project Please come on chat we will discuss more about this I will be waiting for your reply . Thank you !
$251 CAD in 3 days
4.3
4.3

hi, i have reviewed the details of your project. i have experience with rust systems development, api integration, and building data driven tooling. i am comfortable working on security focused research tools in a defensive context, especially around data flow analysis, misconfiguration detection, and correlation logic. i will design a modular rust engine that ingests cve metadata, normalizes it, and builds relationship graphs between different risk classes like auth issues, misconfigurations, and data exposure points. the focus would be on detection and visibility, not exploitation. they would connect in a system, but always from a defensive analysis angle. can we schedule a quick meeting to discuss the architecture in detail. it will help me understand your correlation model better and we can decide the best rust design together. we can do this and then you can decide. mughiraa
$500 CAD in 7 days
4.5
4.5

As a seasoned software engineer with deep knowledge in Rust, I am highly equipped to take on the project of building your sophisticated, Rust-based security research tool. My team and I specialize in delivering AI systems that operate seamlessly within existing workflows to provide tangible value. This level of expertise can be crucial when handling the sensitivity and potential impact of your project. We have proficiency in not just Rust, but all relevant aspects such as systems-level programming, CVE analysis, API interaction, and Database management - necessary skills for creating an effective security detection engine like you're seeking. Furthermore, our track record with deploying on various cloud platforms including AWS, Azure, and GCP will be vital for integration into your existing systems. Our approach aligns perfectly with what you're looking for - thinking in systems rather than focusing on individual bugs. Our aim is to build holistic, robust solutions that address complex problems comprehensively. This philosophy resonates well with this project's need to chain unrelated CVEs for a comprehensive end-to-end assessment of security vulnerabilities.
$500 CAD in 7 days
4.7
4.7

Hello, I've carefully reviewed your project description and am excited about the opportunity to collaborate on building your Rust-based security detection engine that correlates multiple CVEs to simulate real-world attack chains. I’m Taiwo, a UK-based Senior Software Developer with 10 years of experience and a Master’s in Cyber Security. My experience includes working with top companies like IBM, UK Government, BMW, and Sky, where I developed robust systems and understand the importance of system-level thinking and secure coding practices. My skills in Python and experience in other languages and technology can be beneficial. My approach to this project would involve a deep dive into CVE analysis, focusing on identifying and chaining vulnerabilities across different classes, combined with Rust development expertise to build a high-performance detection engine. I am interested in CVE-2021-44228 (Log4Shell) due to its widespread impact. Relevant projects: ⏺ GitSecure – A Security tool that finds, prioritize, and fix vulnerabilities in real-time before they become threats to your code and cloud ⏺IMS Team – built a project and timesheet management system that improved collaboration and workflow efficiency. I'm eager to discuss this project further and explore how we can collaborate to achieve your goals. Kind regards, Taiwo
$600 CAD in 7 days
3.9
3.9

Dear Client, Hello There! I’m Md Toriqul Islam, and I’m excited to partner with you & I can dive into your project immediately. I’m an experienced Rust systems developer specializing in security research tooling, CVE analysis, network protocol handling, and building high-performance systems for vulnerability correlation and detection. I understand you are building a Rust-based security research engine that correlates multiple CVEs across different categories to simulate real-world attack chains leading to data exposure, focusing on chained vulnerabilities rather than isolated exploits. I’ve worked on similar systems-level security analysis and data correlation projects using Rust and network-driven architectures. I am skilled in Rust, CVE analysis, API and database security, and systems programming. I’m ready to start immediately and would be happy to collaborate on designing a scalable and research-focused detection engine. Best regards, Md Toriqul Islam
$250 CAD in 6 days
4.1
4.1

Hi there, thanks for sharing the details on your Rust-based security research tool. I’m Cora May, and I’ve built systems-focused detection and analysis tooling where the core value is correlating evidence across components rather than stopping at single-issue exploits. For your engine, I would implement a Rust detection pipeline that models CVE “nodes” and relationships, then simulates realistic attack chains (e.g., info disclosure → weak SMTP relay → database credential exposure) while producing defender-friendly paths and telemetry fields. I’d also help design safe data handling for sensitive artifacts like API keys, database credentials, and message logs, including strict authorization boundaries and reproducible research workflows. To align with your goals, I can contribute code for parsing CVE metadata, normalizing protocol/API signals, and evaluating correlation rules across email/SMS, SMTP, and database layers.
$555 CAD in 2 days
3.7
3.7

Hello, good day! ?? The goal of this project is to develop a system that can identify and analyze various types of vulnerabilities (CVEs), and simulate real attack chains. We aim to find paths that expose sensitive information like API keys, database details, and logs. This tool will help security teams better understand weaknesses and prevent attacks. Overall, we want to build a strong, scalable system that can handle multiple vulnerabilities together and show potential infiltration routes. What are your thoughts?
$433 CAD in 27 days
3.9
3.9

Hello, After reviewing your Rust security research project, I fully understand the scope and direction. I have experience working with systems-level architectures, API integrations, security-focused backend tooling, and vulnerability analysis workflows, and I’m ready to collaborate immediately. I bring deep expertise in Rust, Software Engineering, API Development, Penetration Testing concepts, Data Protection, Risk Management, and distributed system design with over 10 years of experience. A key point in projects like this is building a correlation engine that models chained exposure paths across services, protocols, and misconfigurations rather than treating CVEs as isolated findings. One CVE class I find especially interesting is information disclosure combined with weak SMTP/API configurations, because seemingly low-severity leaks can become critical when chained with exposed credentials or permissive database access. I have a couple of quick questions: • Will the engine focus primarily on static correlation logic first, or also runtime/environment validation against live systems? • Are you planning the architecture around graph-based relationships between CVEs, services, and assets? I would be glad to contribute on the Rust backend, correlation logic, API/network analysis layers, and defensive research workflows. Looking forward to your reply. Best regards, Carlos
$250 CAD in 7 days
3.6
3.6

Start immediately | Timeline: Initial research framework in 1 week | Budget: $650 CAD fixed Your approach of correlating unrelated CVEs into realistic exposure chains is exactly the kind of systems-level security research that creates meaningful defensive insight. I’m interested in contributing to the Rust-based detection engine, particularly around API/database misconfiguration analysis, attack-path correlation, and scalable rule-processing architecture. Relevant strengths: • Rust for high-performance concurrent tooling • Experience with REST APIs, SMTP workflows, auth flows & database security • Security research focused on misconfigurations, privilege boundaries & data exposure paths • Strong emphasis on modular, testable systems architecture One CVE class I find especially interesting is chained information disclosure leading to credential reuse across internal services — particularly where weak SMTP/API configurations unintentionally expose operational metadata that enables lateral movement. I can contribute clean Rust modules, detection logic, parsers, and correlation workflows while keeping the project aligned with defensive research and authorized testing objectives.
$650 CAD in 7 days
3.3
3.3

❤️Hi there ❤️ As a verified engineer, I can do your project perfect. Please check my reviews to verify my skills. Warm Regards, Ruslan
$500 CAD in 7 days
3.6
3.6

Hi, ⭐15+ Yrs Sr Developer here⭐ I’m experienced in Rust systems programming and building security-focused tools. I can collaborate to develop a detection engine that correlates multiple CVEs across APIs, databases, and SMTP/email systems, simulating real-world attack chains to identify exposure paths. I’ve worked with API integrations, database security, and network protocols, and I think in terms of full-system risk, not isolated exploits. I can contribute clean, efficient Rust code and help map complex attack chains for authorized security research and defensive testing. If you think I am a good fit, feel free to ping me anytime. — GAZMIR
$250 CAD in 3 days
3.1
3.1

Hello, As you know, the main problem of this project is that correlating multiple CVEs effectively requires robust architecture to manage complex data flows and simulate attack chains. I will implement a modular Rust-based detection engine leveraging asynchronous programming for efficient data handling. The architecture will consist of distinct components for CVE ingestion, analysis, and correlation, ensuring scalability. I will manage edge cases by implementing thorough validation checks and logging to trace attack paths. Reusable libraries for API interaction and database access will be integrated, while the core logic will be newly developed to maintain flexibility. The deliverable will be a fully functional Rust application that correlates CVEs and simulates attack chains, complete with documentation and testing coverage. My background includes building security tools in Rust, focusing on systems-level thinking and real-world attack simulations. I can start immediately. Regards.
$500 CAD in 7 days
2.6
2.6

My years of experience as a versatile web and software developer have honed my ability to navigate complex requirements while creating solutions that are efficient and scalable— key ingredients for a project of your magnitude. I impart these skills into all my work, using modern tech stacks, smart architecture, and future-ready solutions --in this case, harnessing the power of Rust to create a powerful security detection engine . My familiarity with API's, databases, and network protocols sets me up well for the project at hand. Having handled an array of projects from e-commerce platforms to IOT apps, I have developed skills that would give your projec a holistic approach beyond just single-bug analysis - perfect for a detection engine built to string together multiple CVEs in an attack chain. Moreover, my value system of "Scaling at the Core" aligns well with the village-builder mindset you seek. I aim not just to complete the task at hand but also ensure that my creation is scalable and contributes to the long-term success of your organization. Let's work together on something meaningful; building technology that helps protect sensitive data while advancing knowledge and defense testing in the world of cybersecurity.
$300 CAD in 5 days
2.6
2.6

⏰ Timeline: 3–5 weeks | Budget: $1,200 ✅ Hi, Core challenge is building a reliable Rust-based correlation engine that can safely model and connect multiple CVEs across different layers (application, network, database, and configuration) into meaningful exposure chains without false positives or unrealistic assumptions. I’d approach this by structuring the system as a modular Rust pipeline where each CVE type is treated as a normalized “risk node” (e.g. privilege escalation, info disclosure, misconfigurations). These nodes would then be analyzed through a rule-based + graph-based engine to identify realistic dependency chains across systems like APIs, SMTP services, and databases. The focus would be on building a clean internal model for vulnerability relationships rather than just scanning or listing CVEs. That means designing a graph structure that can represent how one weakness (like a misconfigured SMTP relay) can amplify another (like a database exposure or credential leak), and then simulate possible attack paths in a controlled, defensive context. I’ve worked on systems-level tooling before where the main challenge was normalizing inconsistent security data into something that can actually be analyzed programmatically instead of just stored or reported. Let’s chat and define the initial model together so we can shape this into a solid research-grade tool from the ground up.
$1,200 CAD in 15 days
2.4
2.4

Hi, I can help develop the Rust based security detection engine with a defensive research focus. I have experience with Rust, systems level architecture, API integrations, database checks, network protocol handling, security tooling, CVE analysis, logging, and modular detection pipelines. I understand the goal is to correlate multiple weak points, such as info leaks, weak SMTP settings, exposed API configs, database misconfigurations, and privilege related findings, then map the possible exposure path clearly for defenders. I would keep the engine focused on authorized testing, safe validation, evidence collection, severity scoring, and useful reporting rather than unsafe exploit automation. One CVE class I find interesting is information disclosure through misconfigured debug or metadata endpoints, because it often becomes the first link in a larger exposure chain. Best regards Ankit
$250 CAD in 2 days
2.6
2.6

Hi Thank you for reaching out, CODE/CVE I can share a Rust sample and discuss CVE-2023-23397 as an example of how one weakness can expand into a broader exposure chain. I’ll build the Rust detection engine to correlate CVEs, API/database misconfigs, and network signals into clear defensive findings; should output be JSON, graph paths, or both? Let’s hop on chat to discuss about project Best, Jayant
$450 CAD in 7 days
2.0
2.0

Brampton, Canada
Member since May 11, 2026
$10-30 USD
₹12500-37500 INR
$2-8 USD / hour
₹1500-12500 INR
₹1500-12500 INR
₹1500-12500 INR
$250-750 USD
₹2000-5000 INR
₹1500-12500 INR
₹12500-37500 INR
₹12500-37500 INR
$10-30 USD
₹37500-75000 INR
₹12500-37500 INR
$200-1000 USD
₹1500-12500 INR
₹1500-12500 INR
$10-30 USD
₹1500-12500 INR
$100-150 USD