Low-Level Engineer · Red Team Operator · Sri Lanka 🇱🇰

Piyusha
Akash

// 0x3xp

Low-level security engineer operating at the boundary where operating systems expose their internals. Primary discipline: AV/EDR evasion — building tooling that operates below the visibility of modern detection engines through custom syscall stubs, direct kernel interaction, and adversary emulation.

operator_profile.c
01/* Piyusha Akash — Low Level Engineer */ 02 03#include <windows.h> 04#include <ntdll.h> 05 06typedef struct { 07  LPCSTR role = "Low Level Engineer"; 08  LPCSTR primary = "AV/EDR Evasion"; 09  LPCSTR ops[] = { 10    "Malware Dev", "Reverse Eng", 11    "Pentest", "Exploit Dev" 12  }; 13  BOOL hireable = TRUE; 14  DWORD ring = 0x00; 15  LPCSTR origin = "LK"; 16} OPERATOR; 17 18// ring-0 or nothing. 19// build it. understand it.
8+Projects
R-0Ring Level
1+Publications
🇱🇰Origin
01 — About

Operator Profile

identity.struct
HANDLE0x3xp
ROLELow Level Engineer
PRIMARYAV/EDR Evasion
LAYERRing-0 / Kernel
FOCUSWin32 Internals
STATUSHIREABLE
LOCATIONSri Lanka 🇱🇰
OPSRED TEAM

I am a low-level security engineer operating at the intersection of Windows OS internals and offensive security. My primary discipline is AV/EDR evasion — understanding how detection engines instrument the OS and engineering techniques that operate outside their visibility.

My research focuses on Windows OS internals — syscall tables, PE structures, callback arrays, and undocumented kernel routines. I build custom tooling in C, C++, and x64 Assembly to document and exploit these mechanisms. I also conduct penetration testing and full-scope red team engagements.

I approach security as a researcher: adversary emulation to harden defenses, reverse engineering to understand tradecraft, and low-level development to push the boundary of what detection engines can observe.

AV/EDR EVASION WIN32 API WINDOWS INTERNALS SYSCALL FORGE CALLBACK ABUSE NTDLL INTERNALS PE FORMAT SHELLCODE DEV ADVERSARY EMULATION PENETRATION TESTING IDA PRO GHIDRA EXPLOIT DEV
02 — Skills

Technical Arsenal

AV / EDR Evasion Windows OS Internals Malware Development Reverse Engineering Exploit Development Penetration Testing
// Languages
C / C++ x86-64 Assembly MASM / NASM Bash / Shell Rust ✦ learning
// AV/EDR Evasion
Direct Syscalls Indirect Syscalls ETW Patching AMSI Bypass Hook Bypass Stack Spoofing Payload Encryption
// OS Layer
NT Internals Win32 API NTDLL Syscall Tables PEB / TEB PE Format Kernel Structures
// Offensive
Process Injection Shellcode Dev Callback Abuse DLL Injection Reflective Loading Token Impersonation
// Analysis Tools
IDA Pro Ghidra WinDbg x64dbg PE-Bear Procmon Frida
// Red Team Ops
Adversary Emulation Network Pentest Cobalt Strike Metasploit OSINT Web App Testing
03 — Projects

Project Portfolio

ARTEMIS
v1.0.0  ·  Syscall Forge Framework  ·  Latest Release

A modular offensive security framework written in C and x86-64 Assembly — operating entirely below the user-mode API layer, rendering EDR hook-based telemetry blind. Features a 14,869-entry SSN database, MASM stub generation, and multi-algorithm encryption.

HUNTER
Dynamic SSN discovery across 14,869 database entries · Win10/11 · x64/x86
BLACKSMITH
MASM-ready stub forge · Direct & Indirect syscall modes · Stack spoofing
CRYPTO VAULT
XOR / Rolling XOR / RC4 — shields stubs from memory scanners & static AV
C x64 ASM MASM Syscall Forge EDR Evasion RC4 SSN Discovery
View on GitHub ↗
05 — Credentials

Professional Certs

SecOps Group
NEW
CBFRPro
Certified Binary Fuzzing & Reverse Engineering Professional — reverse engineering, binary exploitation, real-world methodology.
Verify — ID: 11705476 ↗
Hackviser
CAPT
Certified Associate Penetration Tester — hands-on offensive security, vulnerability assessment, real-world methodology.
Verify Credential ↗
Red Team Leaders
COWA
Certified Offensive Windows API — advanced Win32/NT exploitation, process injection, DLL hijacking, offensive tooling development.
Cisco Network Academy
Introduction to Cybersecurity
Threat landscape, attack vectors, and defensive practices.
Computer Hardware Basics
Hardware fundamentals and component-level understanding for security practitioners.
Getting Started with Packet Tracer
Network simulation, topology design, and Cisco Packet Tracer.
Security Blue Team
Introduction to OSINT
Intelligence gathering, target profiling, and passive reconnaissance methodology.
Introduction to Virtual Machines
Virtualization fundamentals, hypervisor types, and secure lab environment setup.
OPSWAT Academy
Introduction to Cybersecurity
Core security principles and critical infrastructure protection fundamentals.
Linux Foundation
LFS101 — Introduction to Linux
Linux fundamentals, shell, filesystem, process management, system administration.
08 — Interactive Lab

Terminal Session

piyusha@ring0:~/0x3xp
piyusha@ring0:~$
09 — Contact

Let's Collaborate

Open for
Engagements.

Looking for a low-level engineer specializing in AV/EDR evasion, Windows internals, and adversary emulation? Available for red team engagements, malware research, and security consulting.

Available for Engagements
Available For
Red Team Engagements
AV/EDR Evasion Research & Consulting
Malware Development & Analysis
Penetration Testing
Security Research Collaboration
Windows Internals Consulting
// For engagements, reach out via email or LinkedIn.
// All research conducted under authorized scope.
// Response time: 24–48 hours.