Reverse engineering · Windows internals · Offensive research
From user mode to ring 0.
A complete series connecting memory analysis, hooking, Windows drivers and detection surfaces to concrete defensive implications.

Progression
A learning path, not a collection of demos.
Each part builds on the previous concepts and moves one level deeper into the Windows stack.
From high level to kernel
Processes, memory and coordinates.
Injection, hooks and rendering.
Drivers, virtual memory and UM/KM exchange.
Signals, surfaces and EDR implications.
Code & challenge
Artifacts you can inspect.
The repositories accompany the articles. The challenge turns the concepts into a controlled exercise.
These projects are built in controlled labs and published for research and defense. The techniques are presented together with detection surfaces and implications for EDR/antimalware evaluation.
Videos
Demonstration catalog.
Controlled-lab research into drivers, EDR/antivirus surfaces, and internal and external architectures.
Kernel · EDR and antivirus
Internal implementations
External implementations
Continue