We are a non-profit company limited by guarantee (CLG) registered in the United Kingdom. We work in and for civil society, with most of our programmes based in East and South Asia. For U.S.-based funders, we have a valid Equivalency Determination by Latitude Global, and thus are treated as the equivalent of a 501(c)(3) organization for grantmaking purposes.
BARGHEST is a security research team of hackers. We investigate mobile surveillance, targeted malware, and vulnerabilities that put human rights defenders and journalists at risk, particularly in East and South East Asia.
Offensive security research informs what we build. We conduct penetration testing, vulnerability analysis, and reverse engineering. This gives our research and development work a full cycle: we study how spyware and other threats work, then use those findings to build a forensic commons for spyware investigations.
Our findings also shape our open-source forensic tools. WARD helps people collect and review evidence from Android devices. MESH is being built for consent-based remote evidence collection when an investigator cannot reach the device in person.
Our tools are built entirely in house by our own team, which includes some of the best software engineers in the industry. We never outsource development or subgrant it to another organization.
Sensitive evidence should not have to pass through a commercial vendor or a distant specialist before a community can act on it. Our tools are designed around consent, local control, careful handling of evidence, and redaction. Expert review still matters, but it should not be the only way to begin an investigation.
We welcome collaboration with security researchers, developers, human rights groups, helplines, and forensic labs.
Write to info@barghest.asia.
If our work has helped you or improved the security of your product, you can support our research with Bitcoin.
BTC: bc1qsfrk6nqg0fm7ewxe3cwyztw53lpfw6dm7daxzk