I'm a security researcher who lives at the bottom of the stack. My day-to-day is spent tearing apart binaries, walking Windows kernel internals, and turning AI into a weapon for offensive security.
"If you understand how the machine thinks, you control the machine."
I work across the full offensive spectrum — reading game memory at ring-3, emulating kernel drivers at ring-0, and building AI-native autonomous red-teaming at the agent-orchestration layer. I'm the co-owner of PurpleAILAB and its flagship autonomous red-team agent.
| Domain | Focus |
|---|---|
| 🎮 Game Hacking | Memory manipulation, internal/external cheats, anti-cheat bypass (EAC, Vanguard, BattlEye), hooking, PCX Enma/AngelScript automation |
| 🛡️ Penetration Testing | Red team operations, web/mobile/network exploitation, autonomous kill chains |
| 🧨 0-Day Discovery | Vulnerability research, fuzzing, exploit development, variant analysis, patch diffing |
| 🔬 Reverse Engineering | IDA Pro / Ghidra, binary instrumentation, unpacking (Themida/VMProtect), protocol & malware analysis |
| 🪟 Windows Internals | Kernel drivers, manual mapping, injection, hypervisors/EPT/VMCS, DMA attacks (PCILeech/FPGA), BYOVD |
| 🤖 AI / Autonomous Offense | Offensive LLM agents, autonomous red teaming, agent swarms, MCP tooling, LLM security |
🏆 Flagship — Decepticon
Decepticon is a professional autonomous Red Team agent — and I'm a co-owner of the project. Unlike the "AI hacker" demos that run nmap and print a report, Decepticon executes real attack chains — reconnaissance, exploitation, privilege escalation, lateral movement, and C2 — the way a real adversary would.
It operates under the discipline that separates red teamers from script kiddies: before a single packet leaves the wire it generates a complete engagement package — RoE, ConOps, Deconfliction Plan, and OPPLAN with MITRE ATT&CK mapping — and every action runs inside those rules.
Key capabilities:
- 🧵 Real kill chains — reads an OPPLAN and pursues objectives through whatever path opens up, pivoting and chaining techniques
- 💻 Interactive shells, actually — runs every command inside persistent
tmuxsessions with automatic prompt detection (msfconsole, sliver-client, evil-winrm) - 🏝️ Hardened sandbox isolation — all commands run in an isolated Kali sandbox on a dedicated operational network
- 📊 State-of-the-art benchmarks — 102/104 (98.08%) pass rate on XBOW validation-benchmarks
| Project | Description | Stars |
|---|---|---|
| Decepticon | Autonomous Red Team agent — real kill chains, RoE/OPPLAN discipline, 98% XBOW pass rate (co-owner) | |
| Vigilo | AI hacker for Web3 smart contracts — bug bounties, audit contests, real-world exploit thinking | |
| omniwire | Infrastructure layer for AI agent swarms — 88 MCP tools, A2A, OmniMesh VPN, CDP browser, 2FA | |
| free-code | Free build of Claude Code — telemetry removed, guardrails stripped, all experimental features | — |
| Project | Description | Stars |
|---|---|---|
| unleash | Unleash Claude Code — 113 patches, zero refuse/telemetry, 42 gates. Bun SEA bytecode patcher + TUI + 11-strategy signature scanner | |
| Kevlar | x64 Windows kernel-driver emulation & behavior-analysis harness powered by Unicorn Engine | |
| vibe-island | A Dynamic Island for AI coding tools — macOS, Windows, Linux (Hyprland/Sway/GNOME/KDE) | |
| AiDA-Fork | AI-powered assistant for IDA 9.0+ to accelerate reverse engineering of C++ games | |
| VoidChecksum | Security research — RE, pentesting, exploit research, security audits | |
| unknowncheats-mcp | MCP server for UnknownCheats & Elitepvpers with automatic Cloudflare bypass | |
| PCILeechGen | Firmware generator tool for PCILeech DMA attacks | |
| pcileech-fpga | FPGA modules for PCILeech Direct Memory Access (DMA) attack software |
| Project | Description |
|---|---|
| pcx-ai-toolkit | Source-grounded AI toolkit for Perception.cx Enma & AngelScript — verified docs, API oracle, MCP tools, LSP packages |
| enma-lsp-pcx | Zero-setup VS Code LSP for Perception.cx Enma (.em) — IntelliSense, type checking, bundler & DAP debugger |
| codex-patcher-cc | CodexCLI patcher — Rust Mach-O patches + wrapper + config installer |
| coursera-mcp-rs | Coursera MCP server in Rust — 4.9MB binary, 134 tools, async tokio, zero-copy I/O |
| Project | Description |
|---|---|
| flipperone-mcu-firmware | Flipper One MCU firmware sources (RP2350 low-power co-processor) |
| flipper-profile | btrfs+overlayfs OS snapshot/profile manager for Flipper One |
| linux-rk3576-rocket | RFC patch series — RK3576 support for mainline rocket NPU driver |
Offensive Stack: IDA Pro · Ghidra · x64dbg · WinDbg · HyperDbg · PCILeech · Unicorn Engine · Frida · Volatility · Burp Suite · Metasploit · Cobalt Strike
AI / Agent Stack: Claude Code · OpenAI Codex · MCP (Model Context Protocol) · A2A · LangGraph · Agent Swarms · LiteLLM · Prompt Injection & Jailbreak Testing
- 🎮 Deep-diving anti-cheat internals & game engine reversing (Enma / AngelScript automation)
- 🪟 Building kernel-level tooling — driver emulation, manual mapping, hypervisor research
- 🧨 Hunting 0-days across security products & Windows internals
- 🤖 Advancing autonomous red teaming with Decepticon at PurpleAILAB
- 🧊 Expanding PCILeech / DMA / FPGA attack surface
Always looking to collaborate on offensive security research, exploit development, and AI-security projects.





