A software house for high-complexity technical projects.

Botanica designs and builds software for problems without an established solution: research, proof of concept, and production systems, with precision and minimal overhead.

An experienced team of senior software developers and researchers, with expertise spanning kernel internals, program analysis, reverse engineering, cryptography, and AI security. We are battle-tested and ready to deliver.

vim — ~/mosaic.frag

Clients

What we do

We work across AI security, runtime security, program analysis, reverse engineering, cryptography, instrumentation, and security review.

Our team is highly proficient with most contemporary programming languages and tools, including Rust, Go, C, C++, Java, TypeScript, Python, and Solidity, with IDA Pro and mitmproxy where no source is available, and PyTorch and the surrounding ML stack for AI work. If your code involves esoteric technologies in uncommon or unfamiliar environments, we are quick to learn and happy to rise to the occasion.

Portfolio

Botanica has delivered a wide range of projects for a wide range of clients; a selection is described below.

f4a91c7 (HEAD -> main, work/ebpf-agent)

eBPF agent stack

A full eBPF agent stack, developed to instrument and monitor production environments, from kernel-side collection through to the observability pipeline, delivered as a product component.

#observability #ebpf

3e7d0b2 (work/taint-engine)

Cross-language static analysis platform

Taint and flow analysis over arbitrary repositories, including novel static analysis software built for deep comprehension of codebases too large to review manually.

#program-analysis

b81f26e (work/iot-teardown)

Embedded firmware teardown

Reverse engineering of an IoT product ahead of its security audit: components mapped across platforms, weaknesses identified before the external audit.

#firmware #reverse-engineering

92c4d1a (work/jvm-hooks)

JVM instrumentation framework

A prototype for hooking Java programs safely, including injection, data extraction, and a clean integration path to the client’s frontend.

#instrumentation #java

6d0e8f3 (work/apk-recon)

Mobile traffic analysis

Dissection of Android applications and their traffic, to answer specific questions about how they behave.

#mobile #android

c57a219 (work/build-times)

Build system audit

Analysis and rework of a client’s build systems to cut developer idle time.

#developer-platform

1af64d8 (work/chain-integration)

Blockchain integrations

Integration layers against blockchain infrastructure, wiring client systems into on-chain data and transaction flows.

#blockchain

d29b3c5 (work/retro-re)

Obsolete technology research

Reverse engineering of archival software: MFC, VisualBasic, and DOS-era binaries, recovering behaviour for which no documentation survived.

#legacy-systems #reverse-engineering

78e1a4f (work/rust-pwnable)

CTF challenge engineering

A returning engagement: challenges built each year for Microsoft’s BlueHat conference, most recently a pwnable in Rust, around a carefully concealed heap overflow.

#exploitation #ctf

40cbe92 (work/auto-audit)

Automotive security review

A live hybrid audit, with black-box and white-box work in parallel, of a critical car component written in C and Java.

#code-review #automotive

Careers

Botanica is growing a small team of security researchers and engineers who enjoy difficult systems problems, from research through production implementation.

Our open roles are Tel-Aviv-based and hybrid. Find the current openings and application details on our careers page.

Contact

Reach us at hey@botanica.software or through the terminal below.

visitor@botanica: bash
botanica.software #intro · 01/06 TOP