workresearchblogaboutcontact

IMDUI: an immediate-mode C++ UI framework for Windows

Anti-cheat can flag ImGui by its Win32 calls, so we wrote our own immediate-mode C++ UI library for Windows from scratch.

Argus: Kernel memory disclosure through Defender's KSLD process gate

Defender's KSLD driver checks a caller's image path before allowing kernel memory reads. Argus shows why starting from the right executable is a weak reason to trust the code inside it.

Disarming Windows Code Integrity through unprotected .data globals

I followed ci.dll's signing decisions past g_CiOptions and found writable globals that still controlled enforcement. With HVCI off, changing 20 bytes was enough to let unsigned drivers load.

SigmaDrift: a biomechanical replacement for WindMouse

WindMouse paths can look human while their timing gives them away. I built SigmaDrift around motor-control research to model the movement behind the path, with a few deliberate compromises.

Obfuscating kernel drivers without crashing

Kernelcloak brings string encryption and control flow obfuscation into an ordinary WDK build. The challenge was keeping those helpers safe at elevated IRQL without a C runtime.

Why anti-cheats walk your call stack

Hiding a module leaves the problem of explaining how its code got called. I look at what anti-cheats can learn from a stack and why spoofing one return address only goes so far.

Direct circular buffer injection in mouclass.sys

I followed mouse input into mouclass.sys's internal queue. Its spinlock keeps the queue consistent, but the driver does not check who is adding the packets.

ETW as cover traffic for kernel drivers

Windows lets a driver claim an ETW provider identity without proving it. I built a working sampler around that gap to see how far plausible telemetry holds up under inspection.

Patching Claude Code's safety out of cli.js

I traced Claude Code's security research refusals to three strings in cli.js. Changing them was simple. Keeping the changes through npm updates took most of the engineering.

RSA signature validation gap in CI.dll for grandfathered drivers

A legacy validation path checked certificate chains, hashes, and timestamps while accepting a zeroed RSA signature. I broke each component separately to find out where enforcement stopped.