Windows Internals: Check Your Privilege - The Curious Case of ETW’s SecurityTrace Flag
Consuming from Microsoft-Windows-Threat-Intelligence without Antimalware-PPL or kernel patching/driver loading.
Software Engineering and Security Research
Consuming from Microsoft-Windows-Threat-Intelligence without Antimalware-PPL or kernel patching/driver loading.
Interrupt discovery and delivery on Windows on ARM
Analysis of Windows under ARM64: exception/privilege model, virtual memory mechanics, and OS behavior under VHE
Examining the implementation and implication of PAC in user-mode and kernel-mode on ARM64 Windows
Examining the interface by which NT requests the services of SK through the SkBridge project
Using SourcePoint's JTAG debugger to investigate the implementation of Intel CET Shadow Stacks in kernel-mode on Windows
Analysis of NT, Secure Kernel, and SKCI working together to create the initial SECURE_IMAGE object
Dealing with Virtualization-Based Security (VBS), Hypervisor-Protected Code Integrity (HVCI), and Kernel Control Flow Guard (kCFG).
Porting part 2's ChakraCore exploit to Microsoft Edge while defeating ASLR, DEP, CFG, ACG, CIG, and other mitigations.
Leveraging ChakraCore to convert our denial-of-service from part 1 into a read/write primtive and functioning exploit.