Nick / ck0i
koi
nick / koi
~/helz-site $ git checkout e972289
HEAD is now at e972289 redesign
>_
Redesigns
Writing on security research, systems programming, and game development.
Anti-cheat can flag ImGui by its Win32 calls, so we wrote our own immediate-mode C++ UI library for Windows from scratch.
Defender's KSLD driver checks a caller's image path before allowing kernel memory reads. Argus shows why starting from the right executable is a weak reason to trust the code inside it.
I followed ci.dll's signing decisions past g_CiOptions and found writable globals that still controlled enforcement. With HVCI off, changing 20 bytes was enough to let unsigned drivers load.
WindMouse paths can look human while their timing gives them away. I built SigmaDrift around motor-control research to model the movement behind the path, with a few deliberate compromises.
Kernelcloak brings string encryption and control flow obfuscation into an ordinary WDK build. The challenge was keeping those helpers safe at elevated IRQL without a C runtime.
Hiding a module leaves the problem of explaining how its code got called. I look at what anti-cheats can learn from a stack and why spoofing one return address only goes so far.
I followed mouse input into mouclass.sys's internal queue. Its spinlock keeps the queue consistent, but the driver does not check who is adding the packets.
Windows lets a driver claim an ETW provider identity without proving it. I built a working sampler around that gap to see how far plausible telemetry holds up under inspection.
I traced Claude Code's security research refusals to three strings in cli.js. Changing them was simple. Keeping the changes through npm updates took most of the engineering.
A legacy validation path checked certificate chains, hashes, and timestamps while accepting a zeroed RSA signature. I broke each component separately to find out where enforcement stopped.