WinSysManipulator
Windows system manipulation tooling focused on red team tradecraft and evasion.
Loading core modules...
I am an offensive security researcher specializing in exploit development, malware research, and custom tooling for red team operations.
My work spans low-level Windows internals (process injection, EDR evasion, shellcode development, and binary analysis) through web application testing and automated reconnaissance pipelines. I build primarily in C++, Rust, Python, and Go, with a focus on production-ready tools for real engagements.
I develop end-to-end offensive capabilities across initial access, C2 infrastructure, evasion, post-exploitation, and attack surface automation.
Windows system manipulation tooling focused on red team tradecraft and evasion.
Host inspection utility for checking AV/EDR footprints via native Win32 interfaces.
Binary entropy tampering research for evasive executable modification workflows.
Runtime sandbox and analysis-environment detection routines for payload safety checks.
PowerShell project exploring Defender bypass logic in controlled red team labs.
Automated API key leak hunter. Single-command pipeline from subdomain discovery through secret scanning and live key validation.
Collection of Zig projects including API hooking via trampolines and link obfuscation for offensive tooling research.
Overlord server plugin for static site deployment via Vercel, Netlify, and Cloudflare Drop, with lure import, agent staging, and visitor tracking.
Overlord plugin wrapping DFMI for MSI-based payload delivery, including stub, inject, and rogue-mst modules.
Overlord plugin for EvilFontTool font-based document deception, generating HTML, DOCX, and PDF lures from the C2 console.
Overlord build plugin that scans compiled agent binaries for OPSEC issues across PE, ELF, and Mach-O before deployment.
Agent-side native plugin that runs a full host recon sweep on connect and ships structured results back to Overlord.
Domain intelligence and WHOIS enumeration tool for passive recon and target profiling workflows.
Status: Private for now
Automation, tooling, and rapid exploit scripting. Primary language for most security workflows.
High-performance C2 implants, network tools, and concurrent backend services.
Low-level exploit development, shellcode, and performance-critical security research.
Windows post-exploitation tooling, BOFs, and .NET-based offensive capabilities.
Memory-safe systems tooling for custom C2 implant development and network utilities.
โ Powershell, Bash, Lua, Batch
Deepening low-level execution knowledge for exploit dev, shellcode writing, and RE.
Systems-level alternative to C for writing lean, portable offensive tooling.
Primary C2 platforms for red team ops: beacon staging, lateral movement, and payload delivery.
Automated web scanning for initial surface coverage before manual testing.
Custom template development for targeted vuln detection across large attack surfaces.
Static analysis and RE for binary targets, malware samples, and custom shellcode review.
PowerShell-based post-exploitation for Windows environments and AD attacks.
Traffic analysis for protocol-level debugging, C2 detection evasion testing, and pcap review.
Manual web app testing with custom extensions, active scanning, and request manipulation.
Creating custom exploits and shellcode, including 0-day vulnerability research, evasion techniques, and process injection primitives.
Penetration testing, privilege escalation, EDR/AV bypass, and post-exploitation across web, network, and binary targets.
Subdomain enumeration, API fuzzing, secret scanning, and cloud surface mapping using custom automation pipelines.
Binary analysis, memory inspection, and behavioral analysis for vulnerability research and malware understanding.
I'm currently preparing content and will publish technical writeups soon.
Interested in collaborating on cybersecurity projects or need expertise in penetration testing and network security? Feel free to reach out.
[Send Message]