Low-level engineer operating at the boundary where operating systems expose their internals. I build custom syscall stubs, dissect binaries, craft stealthy payloads, and conduct adversary emulation to stress-test real defenses — not a script kiddie, a researcher.
I am a low-level engineer — not a script kiddie, not a tool user. I operate at the boundary where operating systems expose their internals: syscall tables, PE structures, callback arrays, and undocumented kernel routines.
My research focuses on Windows OS internals — understanding what the kernel permits, what EDRs monitor, and where the gaps between them live. I build custom tooling in C, C++, and x64 Assembly to explore and document these mechanisms. I also conduct penetration testing and full-scope red team engagements.
I approach security as a researcher: adversary emulation to harden defenses, reverse engineering to understand tradecraft, and low-level development to push the boundary of what detection can see.
A modular offensive security framework written in C and x86-64 Assembly — operating entirely below the user-mode API layer, rendering EDR hook-based telemetry blind. Features a 14,869-entry SSN database, MASM stub generation, and multi-algorithm encryption.
Original security research into Windows OS internals, undocumented APIs, and offensive techniques. Each entry represents hands-on investigation — not reproduced knowledge, but original findings from working with real systems at the binary level. Documentation of curiosity operating at ring-0.
Looking for a low-level engineer who understands the kernel, thinks like an adversary, and delivers research that actually matters? Available for red team engagements, malware research, and security consulting.