Principal Security Engineer & Low-Level Researcher specializing in Windows kernel internals, reverse engineering, binary analysis, and anti-tamper mechanics.
- Windows Kernel Internals & Drivers: WDM/KMDF driver development, PatchGuard/DSE subversion analysis, bootloader mechanics, and kernel-mode execution guarding.
- Reverse Engineering & Binary Analysis: Static/dynamic analysis (WinDbg, IDA Pro), x86_64/ARM64 assembly, symbol resolution, and binary patching/unpacking[cite: 1].
- Anti-Tamper & Subversion Mechanisms: Analyzing and designing runtime execution isolation, inline hooking detection, anti-debugging, and memory integrity verification[cite: 1].
- UPGDSED — Universal PatchGuard and Driver Signature Enforcement Disable (Co-creator with @hfiref0x).
- DrvMon — Advanced real-time kernel-mode driver monitoring utility (Created with @hfiref0x).
- Noesis Tension — A telemetry-based diagnostic tool for analyzing internal behavioral regimes of large language models during inference.
- Poor Man's FROST Defense — Chrome OPFS RAM Mitigation.
- LDASM64 — x86-64 / VEX / EVEX / XOP instruction length disassembler (maintenance port).
- Thinking Like a Reverse Engineer About Neural Networks — Bridging the gap between reverse engineering and AI.
- NOESIS: Phase I — On Epistemic Stability, Regime Deviation, and the Limits of Post-Hoc Truth
- NOESIS: Phase II — From Ontology to Observability: An Architecture for Epistemic Regime Detection
- NOESIS Tension — Telemetry-Driven Taxonomy of Prompt-Induced Representational Pressures in Large Language Models
- Kernel Detective — Early anti-rootkit / kernel introspection framework (ARK-era tool)
- proxy_dll — CRT initialization trick for hooking protected applications
- ntdll.h — Clean, minimal Windows NT headers (when Windows.h became too heavy)
- old site — Archived articles and notes from the original fyyre.net
- Email: fyyre [at] fyyre [dot] net
- Security: PGP Key
- Open to serious technical collaborations in Windows Internals and reverse code engineering.

