Security Architect & Low-Level Researcher specializing in Windows kernel internals, reverse engineering, anti-tamper mechanics, and LLM behavioral telemetry.
- Windows Kernel Internals & Drivers: WDM/KMDF, PatchGuard/DSE analysis, bootloader mechanics, kernel-mode execution guarding.
- Reverse Engineering & Binary Analysis: WinDbg / IDA, x86_64 (ARM64 as needed), symbol resolution, live process and binary recovery.
- Anti-Tamper & Runtime Isolation: Hook detection, anti-debug, memory integrity, execution-state isolation in high-concurrency clients.
- AI Observability: Telemetry on inference-time regime deviation — activations, attention, KV cache, routing — same diagnostic posture as kernel tracing, applied to black-box models.
- UPGDSED — Universal PatchGuard and Driver Signature Enforcement Disable (Co-creator with @hfiref0x).
- DrvMon — Advanced real-time kernel-mode driver monitoring utility (Created with @hfiref0x).
- Noesis Tension — A telemetry-based diagnostic tool for analyzing internal behavioral regimes of large language models during inference.
- Noesis — A lightweight toolkit for inspecting transformer internals through residual traces, drift metrics, and token-level activation deltas.
- UEFind — Windows x64 WinAPI tools for inspecting Unreal Engine processes.
- XDE 2.0 — z0mbie's eXtended disassembler engine for x86, x86-64, VEX, EVEX, and XOP
- LDASM64 — x86-64, VEX, EVEX, XOP instruction length disassembler (maintenance port).
- secrep — rebuilding sections in unpacked binaries.
- Thinking Like a Reverse Engineer About Neural Networks — Bridging the gap between reverse engineering and AI.
- NOESIS: Phase I — On Epistemic Stability, Regime Deviation, and the Limits of Post-Hoc Truth
- NOESIS: Phase II — From Ontology to Observability: An Architecture for Epistemic Regime Detection
- NOESIS Tension — Telemetry-Driven Taxonomy of Prompt-Induced Representational Pressures in Large Language Models
- Kernel Detective — Early anti-rootkit / kernel introspection framework (ARK-era tool)
- proxy_dll — CRT initialization trick for hooking protected applications
- ntdll.h — Clean, minimal Windows NT headers (when Windows.h became too heavy)
- lin2lua_ct2_3 — Legacy Lineage II CT2.3 Lua Script control
- bdo_extender — Archival snapshot of my BDO Client Extender
- old site — Archived articles and notes from the original fyyre.net
- Email: fyyre [at] fyyre [dot] net
- Security: PGP Key
- Open to serious technical collaborations in Systems Internals and reverse code engineering.