10 published notes
Writing
Projects I've worked on and questions I wanted to understand better. Mostly Windows, security, and reverse engineering.
index / 03
Published notes.
Sorted by publication date. Filter by topic, or follow along with RSS.
10 notes
- 01
IMDUI: an immediate-mode C++ UI framework for Windows
Anti-cheat can flag ImGui by its Win32 calls, so we wrote our own immediate-mode C++ UI library for Windows from scratch.
- 02
Argus: Kernel memory disclosure through Defender's KSLD process gate
Defender's KSLD driver checks a caller's image path before allowing kernel memory reads. Argus shows why starting from the right executable is a weak reason to trust the code inside it.
- 03
Disarming Windows Code Integrity through unprotected .data globals
I followed ci.dll's signing decisions past g_CiOptions and found writable globals that still controlled enforcement. With HVCI off, changing 20 bytes was enough to let unsigned drivers load.
- 04
SigmaDrift: a biomechanical replacement for WindMouse
WindMouse paths can look human while their timing gives them away. I built SigmaDrift around motor-control research to model the movement behind the path, with a few deliberate compromises.
- 05
Obfuscating kernel drivers without crashing
Kernelcloak brings string encryption and control flow obfuscation into an ordinary WDK build. The challenge was keeping those helpers safe at elevated IRQL without a C runtime.
- 06
Why anti-cheats walk your call stack
Hiding a module leaves the problem of explaining how its code got called. I look at what anti-cheats can learn from a stack and why spoofing one return address only goes so far.
- 07
Direct circular buffer injection in mouclass.sys
I followed mouse input into mouclass.sys's internal queue. Its spinlock keeps the queue consistent, but the driver does not check who is adding the packets.
- 08
ETW as cover traffic for kernel drivers
Windows lets a driver claim an ETW provider identity without proving it. I built a working sampler around that gap to see how far plausible telemetry holds up under inspection.
- 09
Patching Claude Code's safety out of cli.js
I traced Claude Code's security research refusals to three strings in cli.js. Changing them was simple. Keeping the changes through npm updates took most of the engineering.
- 10
RSA signature validation gap in CI.dll for grandfathered drivers
A legacy validation path checked certificate chains, hashes, and timestamps while accepting a zeroed RSA signature. I broke each component separately to find out where enforcement stopped.