Vulnerability Research & Disclosures

Background
share close

VULNERABILITY RESEARCH & DISCLOSURES

Original discoveries. Exploit development. Shellcode engineering. Patch intelligence.

This archive documents vulnerabilities I have identified, responsibly disclosed and independently analysed—alongside public exploit development, shellcode engineering, payload research and Windows patch intelligence.

The objective is not simply to list CVEs. It is to preserve the full technical record: what failed, how exploitation primitives were built, how payloads work internally, what changed in the patch, and what defenders can learn from the evidence.

Original Disclosures
Shellcode & Exploits
Patch Analysis

Background
Research Record

FROM DISCOVERY TO DEFENSIBLE UNDERSTANDING

More than 10 zero-day discoveries, public CVE research, responsible vendor disclosure and technical work referenced across industry and security-training ecosystems.


10+

Zero-day discoveries

Original vulnerabilities identified through hands-on product and attack-surface research.

CVE

Public research record

Technical references across NVD, Exploit-DB, Rapid7 and vendor advisories.

ASM

Shellcode and payload research

Assembly-level payload analysis, custom encoding, crypters, polymorphism and exploit-development education.

DIFF

Patch intelligence

Binary comparison, root-cause reasoning, reachability analysis and defensive guidance.

Research Method

FIND WHAT BREAKS. PROVE WHY IT MATTERS. TRANSLATE IT FOR DEFENDERS.

A disciplined workflow that connects technical evidence to real exploitability and defensive action.


01 — Discover

Map attack surfaces, identify trust boundaries, inspect parsers and protocol handlers, and isolate unsafe code paths or behavioural inconsistencies.

02 — Validate

Reproduce the condition safely, establish reachability, identify prerequisites, assess impact, and separate theoretical weakness from demonstrable risk.

03 — Defend

Document root cause, affected versions, patch behaviour, detection opportunities and practical remediation without publishing unnecessary weaponisation detail.

Exploit Development

SHELLCODE ENGINEERING & PAYLOAD RESEARCH

The public research record extends beyond CVEs into exploit construction, payload internals, assembly-level reasoning and evasion-aware shellcode design.


Shellcode engineering

The Art of Shellcoding is a restored nine-part Linux x86 research series spanning bind and reverse shell construction, payload-size optimisation, egghunting, custom encoding, Metasploit payload internals, polymorphism and AES-based encryption. Selected articles include:

Payload internals

Assembly-level analysis explained how established Metasploit payloads operate rather than treating generated shellcode as a black box.

Public exploit archives

Exploit and shellcode work has been published, mirrored or referenced through established offensive-security archives and technical publishing platforms.

Technical Publishing

MAGAZINE ARTICLES & PRACTITIONER EDUCATION

Long-form technical writing across penetration testing, exploit development, wireless forensics, mobile forensics and web-application security.


Selected forensic publications

These articles connected attack techniques with evidence reconstruction, packet analysis and defensible forensic methodology.

Penetration-testing publications

This editorial work predates and complements the book portfolio, showing a sustained history of translating hands-on offensive-security research into material for practitioners and learners.

Original Research

PUBLIC VULNERABILITIES I HAVE IDENTIFIED

Responsible disclosures and technical write-ups covering vulnerabilities discovered through independent research.


Patch Intelligence

PUBLIC VULNERABILITIES I HAVE ANALYSED

Patch-diff research that examines changed code, probable root cause, reachability, exploitability and defensive significance.


External Records

INDEPENDENT RESEARCH REFERENCES

Authoritative public records and third-party repositories containing vulnerability, exploit and acknowledgement references.


Industry acknowledgements

Responsible-disclosure and security-research contributions have been acknowledged by organisations including Apple, AT&T, Facebook, Microsoft, BlackBerry, Rapid7 and Offensive Security.

Disclosure Principles

RESEARCH WITH TECHNICAL DEPTH AND RESPONSIBLE BOUNDARIES


Coordinated disclosure

Vendors are given a reasonable opportunity to investigate and remediate before sensitive technical details are published.

Evidence over speculation

Claims are grounded in reproducible behaviour, patch evidence, code-level observations or authoritative public records.

Defensive value

Public content prioritises root cause, detection, remediation and learning while avoiding unnecessary operational weaponisation.

Research & Collaboration

CONNECT ON VULNERABILITY RESEARCH, PATCH INTELLIGENCE OR TECHNICAL SPEAKING

Available for selected research conversations, conference sessions, media commentary and community collaboration.


Explore My Exploit-DB Research