I research how Windows software crosses trust boundaries and what happens when those boundaries are implemented incorrectly.

My work focuses on:

  • Windows privilege boundaries and local elevation paths
  • Native Windows services and operating-system components
  • C/C++ and .NET binary analysis
  • Installers, privileged services, IPC interfaces, and update mechanisms
  • Industrial and enterprise security software

I combine static and dynamic reverse engineering with code-level analysis to trace attacker-controlled input across service boundaries. The goal is practical: understand the real attack context, demonstrate impact, and give vendors enough detail to reproduce and fix the issue.

Public findings include six CVEs affecting Cisco, BeyondTrust, Hitachi Energy, and AVEVA. The industrial findings are also documented in CISA ICS advisories.