Low-level security engineer operating at the boundary where operating systems expose their internals. Primary discipline: AV/EDR evasion — building tooling that operates below the visibility of modern detection engines through custom syscall stubs, direct kernel interaction, and adversary emulation.
I am a low-level security engineer operating at the intersection of Windows OS internals and offensive security. My primary discipline is AV/EDR evasion — understanding how detection engines instrument the OS and engineering techniques that operate outside their visibility.
My research focuses on Windows OS internals — syscall tables, PE structures, callback arrays, and undocumented kernel routines. I build custom tooling in C, C++, and x64 Assembly to document and exploit these mechanisms. I also conduct penetration testing and full-scope red team engagements.
I approach security as a researcher: adversary emulation to harden defenses, reverse engineering to understand tradecraft, and low-level development to push the boundary of what detection engines can observe.
A modular offensive security framework written in C and x86-64 Assembly — operating entirely below the user-mode API layer, rendering EDR hook-based telemetry blind. Features a 14,869-entry SSN database, MASM stub generation, and multi-algorithm encryption.
Original security research into Windows OS internals, undocumented APIs, and offensive techniques. Each entry represents hands-on investigation — original findings from working with real systems at the binary level.
Looking for a low-level engineer specializing in AV/EDR evasion, Windows internals, and adversary emulation? Available for red team engagements, malware research, and security consulting.