From Day Zero to Zero Day: A Hands-On Guide to Vulnerability Research
Find vulnerabilities before anyone else does.

Zero days aren’t magic—they’re missed opportunities. From Day Zero to Zero Day teaches you how to find them before anyone else does.

In this hands-on guide, award-winning white-hat hacker Eugene “Spaceraccoon” Lim breaks down the real-world process of vulnerability discovery. You’ll retrace the steps behind past CVEs, analyze open source and embedded targets, and build a repeatable workflow for uncovering critical flaws in code.

Whether you’re new to vulnerability research or sharpening an existing skill set, this book will show you how to think—and work—like a bug hunter.

You’ll learn how to:
  • Identify promising targets across codebases, protocols, and file formats.
  • Trace code paths with taint analysis and map attack surfaces with precision.
  • Reverse engineer binaries using Ghidra, Frida, and angr.
  • Apply coverage-guided fuzzing, symbolic execution, and variant analysis.
  • Build and validate proof-of-concept exploits to demonstrate real-world impact.

More than a toolkit, this is a window into how top vulnerability researchers approach the work. You’ll gain not just techniques but also the mindset to go deeper, ask better questions, and find what others miss.

If you’re ready to stop reading write-ups and start writing them, From Day Zero to Zero Day is your guide.
1147489056
From Day Zero to Zero Day: A Hands-On Guide to Vulnerability Research
Find vulnerabilities before anyone else does.

Zero days aren’t magic—they’re missed opportunities. From Day Zero to Zero Day teaches you how to find them before anyone else does.

In this hands-on guide, award-winning white-hat hacker Eugene “Spaceraccoon” Lim breaks down the real-world process of vulnerability discovery. You’ll retrace the steps behind past CVEs, analyze open source and embedded targets, and build a repeatable workflow for uncovering critical flaws in code.

Whether you’re new to vulnerability research or sharpening an existing skill set, this book will show you how to think—and work—like a bug hunter.

You’ll learn how to:
  • Identify promising targets across codebases, protocols, and file formats.
  • Trace code paths with taint analysis and map attack surfaces with precision.
  • Reverse engineer binaries using Ghidra, Frida, and angr.
  • Apply coverage-guided fuzzing, symbolic execution, and variant analysis.
  • Build and validate proof-of-concept exploits to demonstrate real-world impact.

More than a toolkit, this is a window into how top vulnerability researchers approach the work. You’ll gain not just techniques but also the mindset to go deeper, ask better questions, and find what others miss.

If you’re ready to stop reading write-ups and start writing them, From Day Zero to Zero Day is your guide.
59.99 Pre Order
From Day Zero to Zero Day: A Hands-On Guide to Vulnerability Research

From Day Zero to Zero Day: A Hands-On Guide to Vulnerability Research

by Eugene Lim
From Day Zero to Zero Day: A Hands-On Guide to Vulnerability Research

From Day Zero to Zero Day: A Hands-On Guide to Vulnerability Research

by Eugene Lim

Paperback

$59.99 
  • SHIP THIS ITEM
    Available for Pre-Order. This item will be released on August 12, 2025

Related collections and offers


Overview

Find vulnerabilities before anyone else does.

Zero days aren’t magic—they’re missed opportunities. From Day Zero to Zero Day teaches you how to find them before anyone else does.

In this hands-on guide, award-winning white-hat hacker Eugene “Spaceraccoon” Lim breaks down the real-world process of vulnerability discovery. You’ll retrace the steps behind past CVEs, analyze open source and embedded targets, and build a repeatable workflow for uncovering critical flaws in code.

Whether you’re new to vulnerability research or sharpening an existing skill set, this book will show you how to think—and work—like a bug hunter.

You’ll learn how to:
  • Identify promising targets across codebases, protocols, and file formats.
  • Trace code paths with taint analysis and map attack surfaces with precision.
  • Reverse engineer binaries using Ghidra, Frida, and angr.
  • Apply coverage-guided fuzzing, symbolic execution, and variant analysis.
  • Build and validate proof-of-concept exploits to demonstrate real-world impact.

More than a toolkit, this is a window into how top vulnerability researchers approach the work. You’ll gain not just techniques but also the mindset to go deeper, ask better questions, and find what others miss.

If you’re ready to stop reading write-ups and start writing them, From Day Zero to Zero Day is your guide.

Product Details

ISBN-13: 9781718503946
Publisher: No Starch Press
Publication date: 08/12/2025
Pages: 344
Product dimensions: 7.06(w) x 9.31(h) x 0.77(d)

About the Author

Eugene Lim (aka “Spaceraccoon”) is a security researcher and white-hat hacker who has reported hundreds of vulnerabilities across enterprise software, hardware, and cloud services. In 2021, he was one of five researchers selected from a pool of over one million for HackerOne’s H1 Elite Hall of Fame. His research has been featured at Black Hat and DEF CON and in WIRED and The Register.

Table of Contents

Foreword by Jacob Soo
Foreword by Shubham Shah, aka shubs
Introduction
Chapter 0: Day Zero
Chapter 1: Taint Analysis
Chapter 2: Mapping Code to Attack Surface
Chapter 3: Automated Variant Analysis
Chapter 4: Binary Taxonomy
Chapter 5: Source and Sink Discovery
Chapter 6: Hybrid Binary Analysis
Chapter 7: Quick and Dirty Fuzzing
Chapter 8: Coverage-Guided Fuzzing
Chapter 9: Fuzzing Everything
Chapter 10: Beyond Day Zero
From the B&N Reads Blog

Customer Reviews