Nick / ck0i
Windows internals.Behavioral security.
Security researcher and systems programmer.
Windows internals, behavioral detection, low-level systems.
Security research and production engineering across the Windows stack.
Current work covers kernel drivers, reverse engineering, anti-cheat systems, behavioral detection, and real-time graphics.
The portfolio includes published research, production products, and open-source libraries.
EER ≤ 0.001 / 43,216 human trials
Synthetic mouse detection.
Kinematic Features Are All You Need evaluates synthetic mouse trajectories under white-box adversarial optimization.
The 17-feature detector reaches EER ≤ 0.001 and retains separation after five optimization rounds.
Research detailsSelected work.
Systems, products, and research. Each link points to a live project or published result.
- 01 Argus A process-identity flaw in Microsoft Defender's KSLD driver that exposes privileged kernel memory operations. Kernel research
- 02 Reweave A commercial service for transforming and hardening PE binaries with symbol-aware protections. Binary protection
- 03 Kernelcloak Header-only C++17 obfuscation and integrity primitives built for Windows kernel constraints. Open source
- 04 wraith-rs Safe Rust abstractions for Windows process internals, syscalls, scanning, and hook detection. Open source
Technical writing.
All writing
Background.
Programming began at age twelve. Current work spans malware analysis, drivers, behavioral security, and real-time systems.
About Nick