From Day Zero to Zero Day cover

From Day Zero to Zero Day

A Hands-On Guide to Vulnerability Research
by Eugene Lim
June 2025, 344 pp.
ISBN-13: 
9781718503946
Use coupon code PREORDER to get 25% off!

Download Chapter 4: Binary Taxonomy

Look Inside!

From Day Zero to Zero Day back cover
From Day Zero to Zero Day pages 34-35From Day Zero to Zero Day pages 74-75From Day Zero to Zero Day pages 248-249

Zero days aren’t magic—they’re missed opportunities. From Day Zero to Zero Day teaches you how to find them before anyone else does.

In this hands-on guide, award-winning white-hat hacker Eugene “Spaceraccoon” Lim breaks down the real-world process of vulnerability discovery. You’ll retrace the steps behind past CVEs, analyze open source and embedded targets, and build a repeatable workflow for uncovering critical flaws in code.

Whether you’re new to vulnerability research or sharpening an existing skill set, this book will show you how to think—and work—like a bug hunter.

You’ll learn how to:

  • Identify promising targets across codebases, protocols, and file formats.   
  • Trace code paths with taint analysis and map attack surfaces with precision.
  • Reverse engineer binaries using Ghidra, Frida, and angr.
  • Apply coverage-guided fuzzing, symbolic execution, and variant analysis.
  • Build and validate proof-of-concept exploits to demonstrate real-world impact.

More than a toolkit, this is a window into how top vulnerability researchers approach the work. You’ll gain not just techniques but also the mindset to go deeper, ask better questions, and find what others miss.

If you’re ready to stop reading write-ups and start writing them, From Day Zero to Zero Day is your guide.

Author Bio 

Eugene Lim (aka “Spaceraccoon”) is a security researcher and white-hat hacker who has reported hundreds of vulnerabilities across enterprise software, hardware, and cloud services. In 2021, he was one of five researchers selected from a pool of over one million for HackerOne’s H1-Elite Hall of Fame. His research has been featured at Black Hat and DEF CON and in WIRED and The Register.

Table of contents 

Foreword by Jacob Soo
Foreword by Shubham Shah, aka shubs
Introduction
Chapter 0: Day Zero
Chapter 1: Taint Analysis
Chapter 2: Mapping Code to Attack Surface
Chapter 3: Automated Variant Analysis
Chapter 4: Binary Taxonomy
Chapter 5: Source and Sink Discovery
Chapter 6: Hybrid Binary Analysis
Chapter 7: Quick and Dirty Fuzzing
Chapter 8: Coverage-Guided Fuzzing
Chapter 9: Fuzzing Everything
Chapter 10: Beyond Day Zero

The chapters in red are included in this Early Access PDF.

View the Copyright page
View the detailed Table of Contents
View the Index