Malware Development
Loaders, implants, execution primitives, and offensive tooling written with implementation detail.
research areas
Loaders, implants, execution primitives, and offensive tooling written with implementation detail.
Detection-aware tradecraft, telemetry pressure points, call-stack hygiene, and bypass constraints.
PE loading, NT APIs, process memory, thread behavior, and the machinery techniques depend on.
featured research
Multi-gadget pool proxy system in Zig — route arbitrary Win32 API calls through the thread pool with gadget-based return address masking. No implant code on the stack, ever.