pwn.sc Back to home

The research journal.

Implementation changes, failed experiments, and the evidence behind them.

HyperRev: executable-state ownership across concurrent transitions

Windows Kernel · Development log

An invalid instruction address, a lifecycle audit, and the gap between a rebuilt hypervisor component and a validated runtime repair.

Devirtualization: verifying the cumulative artifact without a substituted oracle

Binary Analysis · Investigation log

What a six-driver reverse-engineering project taught me about pseudocode coverage, native closure, and retracting a result that passed the wrong test.

Driver triage: separating correlated heuristics from reachable behavior

Windows Kernel · Development log

A scan of 1,019 driver files exposed a scoring problem: ordinary kernel capabilities were being mistaken for evidence of exploitable access.

Event-log recovery: cursor consistency, decoder agreement, and resume correctness

Systems Engineering · Investigation log

Tracing a stale conversation view to a projection mismatch, then discovering why a successful offline replay was not a complete repair.

Aegis vs AI: the semantic shortcuts that survived.

Aegis · Development log

Masked-state projections, independent-agent recovery, symbolic lifting, and the fixes that stop known failures from reaching production.

Read the development log

Building an honest AI reverse-engineering evaluation.

AI & Research · Development log

Frozen A/B artifacts, external observations, authenticated receipts, and the campaign evidence a local test cannot manufacture.

Fixing PE header growth without moving RVAs.

Binary Rewriting · Development log

A short Optional Header overwrite, shared source-layout normalization, and the regression that caught stale assumptions.

Kernel64: entry paths, stack bounds, and unwind checks.

Windows Kernel · Development log

Why an eight-byte alignment fix required a call-graph proof, and what mapped fixture execution actually validated.

Memory acquisition: measuring the gaps.

Kernel Forensics · Investigation log

Coverage windows, exact code copies, negative controls, and separating an internal PTE write from a public write interface.