Writing / Research & tools

Research log.

Technical writeups, research notes, and tools from my work in systems, malware, and exploitation.

ot security

Why Air-Gapped OT Environments Are Still Insecure

A technical analysis of OT isolation: Stuxnet, TRITON, offline malware channels, industrial protocols, WirelessHART, measurement integrity, and maintenance—with reproducible simulation labs.

kernel exploitation

Exploiting CVE-2025-62215: A Reference-Count Race in the Object Manager

A deep-dive into CVE-2025-62215 — an actively exploited race in ntoskrnl's Object Manager that double-frees the token's SID Values Block, reclaimed with a same-bucket spray and pivoted into a data-only token flip for SYSTEM.

malware analysis

Inside the petshub[.]qa ClickFix: From a Fake CAPTCHA to an ACR Stealer Implant

Full teardown of the petshub[.]qa ClickFix campaign: a fake CAPTCHA that drops a blockchain-resolved macOS stealer and a four-stage Windows chain ending in an ACR Stealer implant flagged by 33/69 engines — Realtek masquerade, Heaven's Gate, and CVE-2024-38193 in tow.

kernel exploitation

Exploiting CVE-2026-21241: A Use-After-Free Race in AFD.sys

A deep-dive into CVE-2026-21241 — a use-after-free race in afd.sys's socket notification path, where a notification object is freed across a spinlock release, reclaimed with a named-pipe spray, and pivoted through kCFG-legal RtlSetBit calls into a KDP-evading SeDebugPrivilege flip and SYSTEM.

kernel exploitation

Exploiting CVE-2024-30088: A TOCTOU Race in the Windows Kernel

A deep-dive into CVE-2024-30088 — a TOCTOU race in ntoskrnl's AuthzBasepCopyoutInternalSecurityAttributes, exploited by flipping a user-memory pointer to redirect the kernel's own copy into kernel space, then pivoting the fixed-value write through an I/O Ring into SYSTEM.

kernel exploitation

Exploiting CVE-2025-7771 in the ThrottleStop Driver: Kernel-Exploitation Series

A complete walkthrough of reverse engineering the ThrottleStop driver, understanding its physical memory read/write IOCTL handlers, and building a data-only privilege escalation exploit — from opening the device to spawning a SYSTEM shell.

kernel exploitation

The Kernel Attack Surface: How Windows Internals Enable Exploitation

A subsystem-by-subsystem map of the Windows kernel attack surface — how the syscall interface, I/O manager, memory manager, object manager, and kernel pool each create exploitable primitives, which techniques still work, and which ones died.

windows internals

Windows Internals You Need To Know Before Kernel Exploitation

Every defense mechanism between a user-mode process and kernel code execution, explained from first principles — PatchGuard, VBS, HVCI, SMEP, SMAP, CET, KASLR, and the rest.

malware analysis

Nanga: Process Telemetry from the Syscall Layer

A kernel-driver approach to malware dynamic analysis that captures process telemetry below user-mode evasion, at the syscall layer.