Research & Innovation
A highly specialized Security Researcher and Systems Engineer focusing on Windows kernel exploitation, anti-cheat evasion, and reverse engineering. The profile demonstrates expert-level knowledge of low-level OS internals, including HVCI, PatchGuard, and driver manipulation, primarily leveraging C and C++ to build offensive security tools and bypass techniques.
The score reflects elite-level specialized knowledge in kernel security (9/10) but is weighed down by low project completeness and documentation standards (3/10). This user is a highly capable researcher whose GitHub prioritizes proof-of-concept exploitation over production-ready software engineering.
The profile demonstrates exceptional technical skill through project descriptions and binary capabilities, but confidence is limited (70/100) because several high-profile repositories (`mhydeath`, `NVDrv`, `Shadow-Regions-Bypass`) lack visible source code or are flagged as incomplete by analysis tools.
Prioritizes exploration over polish
No significant red flags detected.
x64 Dynamic Reverse Engineering Toolkit
Unsigned driver loader using CVE-2018-19320
Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin permissions or kernel drivers.
Demystifying PatchGuard is a comprehensive analysis of Microsoft's security feature called PatchGuard, which is designed to prevent unauthorized modifications to the Windows kernel. The analysis is done through practical engineering, with a focus on understanding PatchGuard's inner workings.
Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes.