Skip to content
View NetVar1337's full-sized avatar
🔬
Reverse Engineering / Exploit Research / Security Audits
🔬
Reverse Engineering / Exploit Research / Security Audits

Organizations

@PurpleAILAB

Block or report NetVar1337

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
NetVar1337/README.md

⚡ NetVar1337

Offensive Security Researcher · Windows Internals · Game Hacking

Typing SVG


X / Twitter GitHub PurpleAILAB Discord


🧬 Who Am I

I'm a security researcher who lives at the bottom of the stack. My day-to-day is spent tearing apart binaries, walking Windows kernel internals, and turning AI into a weapon for offensive security.

"If you understand how the machine thinks, you control the machine."

I work across the full offensive spectrum — reading game memory at ring-3, emulating kernel drivers at ring-0, and building AI-native autonomous red-teaming at the agent-orchestration layer. I'm the co-owner of PurpleAILAB and its flagship autonomous red-team agent.


🎯 Specialties

Domain Focus
🎮 Game Hacking Memory manipulation, internal/external cheats, anti-cheat bypass (EAC, Vanguard, BattlEye), hooking, PCX Enma/AngelScript automation
🛡️ Penetration Testing Red team operations, web/mobile/network exploitation, autonomous kill chains
🧨 0-Day Discovery Vulnerability research, fuzzing, exploit development, variant analysis, patch diffing
🔬 Reverse Engineering IDA Pro / Ghidra, binary instrumentation, unpacking (Themida/VMProtect), protocol & malware analysis
🪟 Windows Internals Kernel drivers, manual mapping, injection, hypervisors/EPT/VMCS, DMA attacks (PCILeech/FPGA), BYOVD
🤖 AI / Autonomous Offense Offensive LLM agents, autonomous red teaming, agent swarms, MCP tooling, LLM security

🏆 Flagship — Decepticon

"Another AI hacker? Let us guess — it runs nmap and writes a report."

Stars Forks License

Decepticon is a professional autonomous Red Team agent — and I'm a co-owner of the project. Unlike the "AI hacker" demos that run nmap and print a report, Decepticon executes real attack chains — reconnaissance, exploitation, privilege escalation, lateral movement, and C2 — the way a real adversary would.

It operates under the discipline that separates red teamers from script kiddies: before a single packet leaves the wire it generates a complete engagement package — RoE, ConOps, Deconfliction Plan, and OPPLAN with MITRE ATT&CK mapping — and every action runs inside those rules.

Key capabilities:

  • 🧵 Real kill chains — reads an OPPLAN and pursues objectives through whatever path opens up, pivoting and chaining techniques
  • 💻 Interactive shells, actually — runs every command inside persistent tmux sessions with automatic prompt detection (msfconsole, sliver-client, evil-winrm)
  • 🏝️ Hardened sandbox isolation — all commands run in an isolated Kali sandbox on a dedicated operational network
  • 📊 State-of-the-art benchmarks102/104 (98.08%) pass rate on XBOW validation-benchmarks

Website · Docs · Live App


🔥 Featured Projects

AI & Autonomous Offense

Project Description Stars
Decepticon Autonomous Red Team agent — real kill chains, RoE/OPPLAN discipline, 98% XBOW pass rate (co-owner) 5k
Vigilo AI hacker for Web3 smart contracts — bug bounties, audit contests, real-world exploit thinking 60
omniwire Infrastructure layer for AI agent swarms — 88 MCP tools, A2A, OmniMesh VPN, CDP browser, 2FA 16
free-code Free build of Claude Code — telemetry removed, guardrails stripped, all experimental features

Low-Level / Offensive Security

Project Description Stars
unleash Unleash Claude Code — 113 patches, zero refuse/telemetry, 42 gates. Bun SEA bytecode patcher + TUI + 11-strategy signature scanner 61
Kevlar x64 Windows kernel-driver emulation & behavior-analysis harness powered by Unicorn Engine 2
vibe-island A Dynamic Island for AI coding tools — macOS, Windows, Linux (Hyprland/Sway/GNOME/KDE) 68
AiDA-Fork AI-powered assistant for IDA 9.0+ to accelerate reverse engineering of C++ games 1
VoidChecksum Security research — RE, pentesting, exploit research, security audits 5
unknowncheats-mcp MCP server for UnknownCheats & Elitepvpers with automatic Cloudflare bypass 4
PCILeechGen Firmware generator tool for PCILeech DMA attacks 1
pcileech-fpga FPGA modules for PCILeech Direct Memory Access (DMA) attack software 1

Reverse Engineering Tooling

Project Description
pcx-ai-toolkit Source-grounded AI toolkit for Perception.cx Enma & AngelScript — verified docs, API oracle, MCP tools, LSP packages
enma-lsp-pcx Zero-setup VS Code LSP for Perception.cx Enma (.em) — IntelliSense, type checking, bundler & DAP debugger
codex-patcher-cc CodexCLI patcher — Rust Mach-O patches + wrapper + config installer
coursera-mcp-rs Coursera MCP server in Rust — 4.9MB binary, 134 tools, async tokio, zero-copy I/O

Hardware & Firmware

Project Description
flipperone-mcu-firmware Flipper One MCU firmware sources (RP2350 low-power co-processor)
flipper-profile btrfs+overlayfs OS snapshot/profile manager for Flipper One
linux-rk3576-rocket RFC patch series — RK3576 support for mainline rocket NPU driver

🛠️ Technology Arsenal

C C++ Rust Go Python TypeScript Verilog

Offensive Stack: IDA Pro · Ghidra · x64dbg · WinDbg · HyperDbg · PCILeech · Unicorn Engine · Frida · Volatility · Burp Suite · Metasploit · Cobalt Strike

AI / Agent Stack: Claude Code · OpenAI Codex · MCP (Model Context Protocol) · A2A · LangGraph · Agent Swarms · LiteLLM · Prompt Injection & Jailbreak Testing


📈 GitHub Analytics


GitHub Streak


🏆 Trophies

trophy


🐍 Contribution Graph

github contribution snake svg github contribution snake svg


🧭 Current Mission

  • 🎮 Deep-diving anti-cheat internals & game engine reversing (Enma / AngelScript automation)
  • 🪟 Building kernel-level tooling — driver emulation, manual mapping, hypervisor research
  • 🧨 Hunting 0-days across security products & Windows internals
  • 🤖 Advancing autonomous red teaming with Decepticon at PurpleAILAB
  • 🧊 Expanding PCILeech / DMA / FPGA attack surface

Always looking to collaborate on offensive security research, exploit development, and AI-security projects.


   ┌───────────────────────────────────────────────────────┐
   │  if you understand the machine, you become the machine │
   └───────────────────────────────────────────────────────┘

⚡ Stay sharp. Stay low-level. — NetVar1337

Visitor Badge X

Pinned Loading

  1. PurpleAILAB/Decepticon PurpleAILAB/Decepticon Public

    Autonomous Hacking Agent for Red Team

    Python 5k 976

  2. omniwire omniwire Public

    Infrastructure layer for AI agent swarms — 88 MCP tools · A2A · OmniMesh VPN · Scrapling scraper · COC sync · nftables firewall · CDP browser · 2FA TOTP · ~80ms

    TypeScript 16 9

  3. unleash unleash Public

    Unleash Claude Code. 113 patches — zero refusals, zero telemetry, 42 feature gates unlocked. In-place Bun SEA bytecode patcher with interactive TUI, 11-strategy signature scanner, and auto-discover…

    Go 61 14

  4. Vigilo Vigilo Public

    Forked from PurpleAILAB/Vigilo

    An AI hacker for Web3 Smart Contract. for bug bounties, Audit contest, offensive security research, and real-world exploit thinking.

    TypeScript 3

  5. decepticon-ghidra-mcp decepticon-ghidra-mcp Public

    Most complete Ghidra MCP — 36 tools across P-code, BSim, Version Tracking, emulation, custom types. Built for agentic 0-day discovery.

    Java 3

  6. pcx-ai-toolkit pcx-ai-toolkit Public

    Source-grounded AI toolkit for Perception.cx Enma and AngelScript: verified docs, API oracle, validators, MCP tools, templates, skills, and LSP packages

    Python 13 1