Security Researcher
warbird-hook. Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard
269microsoft-warbird. Reimplementation of Microsoft's Warbird obuscator
223promon-reversal. Analysis and proof-of-concept bypass of Promon SHIELD's Android application protection
215windows-software-policy. Research on obfuscated licensing APIs / CLIP service in the Windows kernel
145warbird-obfuscator. Integration of Microsoft Warbird with the MSVC compiler
133VMP3-Disasm. Experimental disassembler for x86 binaries virtualized by VMProtect 3
97BadlionLogger. kernel driver used to monitor the activity of BadlionAnticheat.sys by patching its IAT
32GD-Editor-Leak. reverse engineered structures and editor code needed to reimplement the editor in the 2019 Geometry Dash 2.2 leaks
32photon. Photon is a hooking engine for ARM
7ghidra-gdt. Ghidra script for generating Ghidra Data Type (GDT) archives containing type information
3x86-Code-Virtualizer. x86 Binary Code Virtualization Tool
3SimpleMemoryWrapper. Simple wrapper for the Windows API, its main objective is to document my learning
2StudentVue-rs. Unofficial Rust API for StudentVUE
2warbirdvm. An analysis of the Warbird virtual-machine protection for the CI!g_pStore
2machkit. Mach library wrapper written in C++
1VMPROTECT. Obfuscation method using virtual machine.
1HEVD-practice. short personal writeups for Hacksys Extreme Vulnerable Driver (HEVD)
1psi-secure-admin-unlock. Revealing an undocumented admin control panel in PSI Secure Browser
1