~/writing
My writing.
I write about projects I've worked on and questions I wanted to understand better. Most posts cover Windows, security, and reverse engineering.
- 01 IMDUI: an immediate-mode C++ UI framework for Windows Anti-cheat can flag ImGui by its Win32 calls, so we wrote our own immediate-mode C++ UI library for Windows from scratch.
- 02 Argus: Kernel memory disclosure through Defender's KSLD process gate Defender's KSLD driver checks a caller's image path before allowing kernel memory reads. Argus shows why starting from the right executable is a weak reason to trust the code inside it.
- 03 Disarming Windows Code Integrity through unprotected .data globals I followed ci.dll's signing decisions past g_CiOptions and found writable globals that still controlled enforcement. With HVCI off, changing 20 bytes was enough to let unsigned drivers load.
- 04 SigmaDrift: a biomechanical replacement for WindMouse WindMouse paths can look human while their timing gives them away. I built SigmaDrift around motor-control research to model the movement behind the path, with a few deliberate compromises.
- 05 Obfuscating kernel drivers without crashing Kernelcloak brings string encryption and control flow obfuscation into an ordinary WDK build. The challenge was keeping those helpers safe at elevated IRQL without a C runtime.
- 06 Why anti-cheats walk your call stack Hiding a module leaves the problem of explaining how its code got called. I look at what anti-cheats can learn from a stack and why spoofing one return address only goes so far.
- 07 Direct circular buffer injection in mouclass.sys I followed mouse input into mouclass.sys's internal queue. Its spinlock keeps the queue consistent, but the driver does not check who is adding the packets.
- 08 ETW as cover traffic for kernel drivers Windows lets a driver claim an ETW provider identity without proving it. I built a working sampler around that gap to see how far plausible telemetry holds up under inspection.
- 09 Patching Claude Code's safety out of cli.js I traced Claude Code's security research refusals to three strings in cli.js. Changing them was simple. Keeping the changes through npm updates took most of the engineering.
- 10 RSA signature validation gap in CI.dll for grandfathered drivers A legacy validation path checked certificate chains, hashes, and timestamps while accepting a zeroed RSA signature. I broke each component separately to find out where enforcement stopped.
rss.xml · follow new posts with RSS