Superfetch Is the Index: A User-Mode Physical Memory Read on Windows
How Superfetch page metadata and an Object Manager redirect turn an NLS section lookup into a privileged, read-only physical-memory view, and where the technique stops.
Blog Archive
Long-form writing on Windows internals, reverse engineering, firmware emulation, and security engineering.
Browse by Tag
How Superfetch page metadata and an Object Manager redirect turn an NLS section lookup into a privileged, read-only physical-memory view, and where the technique stops.
A kernel-grounded detector for raw and gadgeted direct syscalls using process instrumentation callbacks, runtime syscall catalogs, ThreadLastSystemCall, and return-provenance matching.
A reverse-engineering walk through normal user-mode crash reporting, from kernel exception dispatch through in-process WER state, service coordination, and crash-vertical worker creation.
A Windows Object Manager case study in bypassing named-mutex single-instance checks by enumerating, duplicating, and closing remote handles, with EDR hunting caveats.
How compile-time equivalence classes, seeded operator variants, SIMD backends, and Z3 proofs can shift brittle static signatures without pretending behavior disappears.
A disclosure-safe look at using rootless Podman, QEMU user-mode, proot, and AI-assisted triage to build an evidence-preserving firmware lab before trusting router vulnerability findings.