Systems Security Research

Understanding how software behaves below the application layer, from source and build configuration to binaries, memory, system calls, firmware, and runtime behavior.

$ readelf -h target.bin
  Class:     ELF64
  Machine:   AArch64
  Entry:     0x0000000000401c30

$ objdump -d target.bin | grep call
  401c44: bl  0x402100 <sub_402100>

$ gdb -q target.bin
  (gdb) b *0x401c30
  Breakpoint 1 at 0x401c30

Core Areas

The systems I study vary widely, but the underlying approach remains the same: understand the implementation, identify the trust boundaries, test the assumptions, and validate the result.

Reverse Engineering & Native Binary Analysis

Analysis of compiled software across x86, x86 64, ARM, and AArch64 targets through disassembly, symbol analysis, control flow tracing, binary comparison, and runtime investigation.

Embedded Linux & System Internals

Investigation of processes, memory, permissions, IPC, capabilities, seccomp, device interfaces, and kernel facing behavior to understand how security boundaries are enforced at runtime.

Firmware & Device Analysis

Firmware extraction, filesystem analysis, boot process investigation, driver and ioctl mapping, and correlation between published source code and compiled components.

Source Code Security Analysis

Security review of C, C++, Rust, and Go codebases, focusing on memory safety, authorization logic, parsers, configuration, dependencies, and security critical control flow.

Debugging, Fuzzing & Fault Analysis

Crash investigation and fault analysis using GDB, AddressSanitizer, libFuzzer, AFL++, custom harnesses, mutation, differential testing, and controlled reproduction.

Android & Native Runtime Analysis

Analysis of Android applications, native libraries, manifests, APEX components, IPC, and runtime behavior using static analysis, ADB, Frida, and native debugging techniques.

AI & LLM Security Analysis

Evaluation of prompt injection, instruction hierarchy, contextual manipulation, information disclosure, and file based injection across conversational and document based interactions.

Web and API Security

Security assessment of web applications and APIs, including authentication, authorization, access control, input handling, protocol behavior, and server side trust boundaries.

Full Stack Development

Designing web applications as complete systems, from interactive interfaces and application logic to APIs, data persistence, authentication, and deployment. My development work spans React and TypeScript on the frontend, with backend systems built using Node.js, Laravel, Spring Boot, and other server side frameworks, supported by relational databases such as PostgreSQL.

Methodology

The same five stage process, regardless of the system under analysis.

1

Observe

Establish the component, version, architecture, and trust boundaries involved.

2

Understand

Combine source, build configuration, and static analysis into a working model.

3

Hypothesize

Develop a specific and testable explanation for the observed behavior.

4

Reproduce

Build a controlled proof of concept, isolate the relevant variables, and reproduce the behavior consistently.

5

Validate

Confirm root cause and impact, test alternative explanations, and discard conclusions that are not supported by evidence.

Selected Technical Work

Native Binary Analysis

Reverse engineering compiled native libraries through symbol inspection, disassembly, control flow tracing, runtime debugging, memory inspection, and root cause analysis.

Embedded Driver Analysis

Mapping device interfaces and ioctl paths while comparing kernel source with compiled drivers to determine which code paths are actually reachable.

Firmware Analysis

Extracting firmware and system images, identifying executable components and filesystems, and investigating how embedded software interacts with the underlying platform.

Structured File & Parser Analysis

Reverse engineering binary formats and creating controlled valid and malformed inputs to study parser boundaries, validation behavior, and memory safety properties.

Systems Fuzzing

Building instrumented targets with Clang, AddressSanitizer, libFuzzer, and AFL++, using structured seed inputs, custom mutation logic, crash triage, and reproducibility testing.

Source & Dependency Analysis

Tracing security sensitive behavior across Rust, Go, C, and C++ codebases while resolving build configuration, dependency revisions, feature flags, and security advisories.

LLM Security Evaluation

Testing how language models respond to direct and indirect instructions, contextual changes, persona shifts, multi turn interaction, and instructions embedded within documents.

Full Stack Development

Developing complete web platforms that connect user interfaces with application services, databases, external APIs, and automated workflows. Work includes Next.js and React applications, Sanity based content platforms, REST API integration, server side services, database driven features, authentication systems, and cloud deployment.

Toolchain

Languages

CC++RustGoPythonBashJavax86 AssemblyARM Assembly

Binary & Debugging

radare2GDBobjdumpreadelfnmstringsfilelddchecksecstracexxd

Embedded & Android

ADBapktoolJADXaapt/aapt2QEMUFridaAndroid Emulator

Systems & Infrastructure

LinuxDockerQEMUFirecracker conceptsnamespacesseccompLinux capabilities

Fuzzing & Validation

Clang/LLVMAddressSanitizerlibFuzzercustom mutation harnessesdifferential testing

Network & Protocols

curlOpenSSLmitmproxyjqRESTgRPCJSON-RPCHTTP/HTTPSOAuth2/OIDC

Source & Build Analysis

GitCMakeCargoKconfigCargo AuditRustSec advisory database

Full Stack Development

ReactTypeScriptNext.jsNode.jsLaravelSpring BootExpressNestJSPostgreSQLMySQLMongoDBSanityREST APIsTailwind CSSGitVerceln8nCloudflareDNSDomain IntegrationSSL/TLSWeb HostingAnalyticsAdvertising & Ad Networks