~/writing

My writing.

I write about projects I've worked on and questions I wanted to understand better. Most posts cover Windows, security, and reverse engineering.

10 articles 145 minutes of reading 2025 to 2026

10 articles

  1. 01 IMDUI: an immediate-mode C++ UI framework for Windows Anti-cheat can flag ImGui by its Win32 calls, so we wrote our own immediate-mode C++ UI library for Windows from scratch.
  2. 02 Argus: Kernel memory disclosure through Defender's KSLD process gate Defender's KSLD driver checks a caller's image path before allowing kernel memory reads. Argus shows why starting from the right executable is a weak reason to trust the code inside it.
  3. 03 Disarming Windows Code Integrity through unprotected .data globals I followed ci.dll's signing decisions past g_CiOptions and found writable globals that still controlled enforcement. With HVCI off, changing 20 bytes was enough to let unsigned drivers load.
  4. 04 SigmaDrift: a biomechanical replacement for WindMouse WindMouse paths can look human while their timing gives them away. I built SigmaDrift around motor-control research to model the movement behind the path, with a few deliberate compromises.
  5. 05 Obfuscating kernel drivers without crashing Kernelcloak brings string encryption and control flow obfuscation into an ordinary WDK build. The challenge was keeping those helpers safe at elevated IRQL without a C runtime.
  6. 06 Why anti-cheats walk your call stack Hiding a module leaves the problem of explaining how its code got called. I look at what anti-cheats can learn from a stack and why spoofing one return address only goes so far.
  7. 07 Direct circular buffer injection in mouclass.sys I followed mouse input into mouclass.sys's internal queue. Its spinlock keeps the queue consistent, but the driver does not check who is adding the packets.
  8. 08 ETW as cover traffic for kernel drivers Windows lets a driver claim an ETW provider identity without proving it. I built a working sampler around that gap to see how far plausible telemetry holds up under inspection.
  9. 09 Patching Claude Code's safety out of cli.js I traced Claude Code's security research refusals to three strings in cli.js. Changing them was simple. Keeping the changes through npm updates took most of the engineering.
  10. 10 RSA signature validation gap in CI.dll for grandfathered drivers A legacy validation path checked certificate chains, hashes, and timestamps while accepting a zeroed RSA signature. I broke each component separately to find out where enforcement stopped.

rss.xml · follow new posts with RSS