Skip to content
View Fyyre's full-sized avatar
  • United States

Block or report Fyyre

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
fyyre/README.md

James (Fyyre)

Kernel & Reverse Engineering Researcher

Principal Security Engineer & Low-Level Researcher specializing in Windows kernel internals, reverse engineering, binary analysis, and anti-tamper mechanics.


Core Focus Areas

  • Windows Kernel Internals & Drivers: WDM/KMDF driver development, PatchGuard/DSE subversion analysis, bootloader mechanics, and kernel-mode execution guarding.
  • Reverse Engineering & Binary Analysis: Static/dynamic analysis (WinDbg, IDA Pro), x86_64/ARM64 assembly, symbol resolution, and binary patching/unpacking[cite: 1].
  • Anti-Tamper & Subversion Mechanisms: Analyzing and designing runtime execution isolation, inline hooking detection, anti-debugging, and memory integrity verification[cite: 1].

Collaborative Projects

  • UPGDSED — Universal PatchGuard and Driver Signature Enforcement Disable (Co-creator with @hfiref0x).
  • DrvMon — Advanced real-time kernel-mode driver monitoring utility (Created with @hfiref0x).

AI Observability

  • Noesis Tension — A telemetry-based diagnostic tool for analyzing internal behavioral regimes of large language models during inference.

Misc / Utilities


Research & Publications


Historical Projects

  • Kernel Detective — Early anti-rootkit / kernel introspection framework (ARK-era tool)
  • proxy_dll — CRT initialization trick for hooking protected applications
  • ntdll.h — Clean, minimal Windows NT headers (when Windows.h became too heavy)
  • old site — Archived articles and notes from the original fyyre.net

Connect

  • Email: fyyre [at] fyyre [dot] net
  • Security: PGP Key
  • Open to serious technical collaborations in Windows Internals and reverse code engineering.

Pinned Loading

  1. hfiref0x/UPGDSED hfiref0x/UPGDSED Public archive

    Universal PatchGuard and Driver Signature Enforcement Disable

    C 875 262

  2. DrvMon DrvMon Public

    Advanced driver monitoring utility.

    C 215 54

  3. noesis-tension noesis-tension Public

    Telemetry-based taxonomy of how LLMs strain, drift, and hallucinate — measured from layer activations, attention, KV cache, and MoE routing.

    Python 1

  4. noesis noesis Public

    Noesis - A lightweight toolkit for inspecting transformer internals through residual traces, layer-wise drift metrics, and token-level activation deltas

    Python 4

  5. kerneldetective kerneldetective Public

    Kernel Detective

    C 154 72

  6. rce_ai_ml rce_ai_ml Public

    Thinking Like a Reverser About Neural Networks

    4 2