Latest Post
View all →Paint It Blue: Reversing Win32k's Callbacks
A reverse-engineering tour of modern Win32k architecture, x64 syscall dispatch, GUI-thread conversion, and the session-aware callbacks behind GDI batching and other executive callouts.
Read post →
Open Source Projects
GitHub →Silverseal
Silverseal is a Linux framework containing a bootkit, rootkit loader and a rootkit.
View on GitHub →Nidhogg
Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.
View on GitHub →NovaHypervisor
Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with VMware and Hyper-V.
View on GitHub →Cronos
A sleep obfuscation technique leveraging waitable timers to evade memory scanners.
View on GitHub →Sandman
An NTP-based backdoor for operations in hardened networks.
View on GitHub →Venom
A library performing evasive communication using a stolen browser socket.
View on GitHub →