Skip to content
fl0sec

Info

About

fl0sec is a research notebook on reverse engineering, Windows internals, kernel development and offensive security. Posts are long-form and technical: the goal is that each one leaves you able to reproduce the work, not just nod along to it.

What you will find here

  • ReversingStatic and dynamic analysis, unpacking, decompiler archaeology.
  • Windows InternalsUndocumented structures, syscalls, loader and process mechanics.
  • KernelRing 0: drivers, callbacks, PatchGuard, and the objects beneath.
  • ExploitationMemory corruption, primitives, mitigations and how they bend.
  • Malware AnalysisSample teardowns, C2 protocols, evasion and detection surface.
  • WriteupsCTF solutions and research notes worth keeping.

Difficulty ratings

Every article carries a difficulty from 1 to 5. It describes the background assumed by the writeup, not the target's advertised rating — a level 5 post assumes specialist experience and skips the introductions.

Ethics

Everything published here is defensive and educational in intent: understanding how a mechanism works is the prerequisite for both attacking and defending it. Research touching third-party products follows coordinated disclosure, and nothing is published before a fix has shipped.

Articles
1
Words
5,878
Categories
6
Tracking
none