Exploiting HackSys Extreme Vulnerable Driver (HEVD) on Windows 7 x86: a kernel stack buffer overflow using token-stealing shellcode, and privilege escalation via a Write-What-Where overwrite of the HalDispatchTable
Static reverse engineering of two 32-bit PE binaries identified as Ryuk ransomware (Hermes variant). Covers the dropper/loader and the encryption payload, including persistence, process injection, and VSS deletion behavior.
Analysis of an Integer Overflow (SMBGhost) and an uninitialized kernel memory leak (SMBleed) in the SMBv3.1.1 decompression routine, and a Pre-Auth RCE achieved by chaining the two bugs