Low-level systems and memory work
Kernel-adjacent code, anti-analysis stacks, hardware-input pipelines. The fragile, undocumented surfaces most projects route around. Trace tools, kernel debuggers, raw syscalls. I lean in here.
Three years of C++, computer vision, and low-level Windows work. Custom-trained detection models, hardware-level automation, real-time GPU inference. Small commissions, long threads, honest scopes.
Every project below started as a stubborn personal itch and ended as a build that runs. No frameworks of the week, no half-finished side quests.
The largest thing I've been part of. A commercial external for Overwatch 2, built for a private buyer alongside the lead engineer. Under active development.
Under NDA — visuals stay confidential until sale.
Read caseA full external for Counter-Strike 2. Read-only memory, hardware-input automation, a custom ImGui overlay, and four-tier anti-analysis. Combat, visuals, utility, security. One binary, one author.
A computer-vision successor to the original colour detector. Hand-tuned heuristics replaced by a custom-trained neural model, real-time GPU inference, fed by an in-house capture pipeline.
Fully external, GPU-accelerated automation with zero memory interaction. DXGI desktop duplication, a custom HLSL compute shader, hardware-level input.
A full OSINT platform delivered as a Telegram bot: breach search, network recon, threat intel, forensics. One command-driven interface, a credit system, and a public REST API.
In flight — engineering only, no ship yet.
A minimal Type-1 hypervisor loaded as a UEFI application. The guest is the caller itself, so the OS boots straight under our control. Live bring-up: VMCB configuration, 512 GiB identity-mapped NPT, MSR and I/O permission maps, VMRUN dispatch.
A from-scratch, self-hosted licensing and auth backend. Server-authoritative trust, no recoverable secrets in the client, and signed replay-proof responses that kill the classic "fake-server emulator" crack. Go server, C++ SDK on Ed25519 via TweetNaCl.
Most commissions sit at the seam between two of these. The interesting work usually lives in the friction.
Kernel-adjacent code, anti-analysis stacks, hardware-input pipelines. The fragile, undocumented surfaces most projects route around. Trace tools, kernel debuggers, raw syscalls. I lean in here.
Custom-trained detection models, hand-labelled in-house datasets, real-time GPU inference end to end.
Game-side automation that never touches the game process. Capture, compute, hardware input, and anti-analysis where it matters.
Investigation platforms, breach search, internal command-driven tooling. The unglamorous infrastructure that keeps everything else moving.
No frameworks of the week. Three primary languages, one operating-system layer, and a long debugger session for everything else.
Every project here started as a stubborn personal itch. Sair began as wanting to see if memory work could be done without ever touching a write. Colorbot was a Saturday project to learn HLSL. The OSINT bot happened because nobody else's tooling did what I needed.
The work is patient. I read the disassembly, I trace one frame end to end, I write the smallest test that reproduces it, I fix the smallest thing that explains it. The code is rarely glamorous. The compounding is.
If your problem looks like one of mine, the contact button is below.
Small, direct, and honest about scope. You talk to the person writing the code, start to finish.
A short call or thread. I tell you plainly whether it is buildable, roughly how long, and where the risk sits. No sales pitch.
Fixed milestones, working builds you can run, and a running thread. You see the disassembly-level detail if you want it.
Signed binaries, full source where the deal includes it, a short technical writeup, and a window for fixes after handover.
Two lines currently in the pipeline. Details when there are details.
Commission work, source requests, or just to talk about low-level stuff. I read every message.