Skip to content
View Fyyre's full-sized avatar
  • United States

Block or report Fyyre

Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
fyyre/README.md

James (Fyyre)

Kernel & Reverse Engineering Researcher

Principal Security Engineer & Low-Level Researcher specializing in Windows kernel internals, reverse engineering, binary analysis, and anti-tamper mechanics.


Core Focus Areas

  • Windows Kernel Internals & Drivers: WDM/KMDF driver development, PatchGuard/DSE subversion analysis, bootloader mechanics, and kernel-mode execution guarding.
  • Reverse Engineering & Binary Analysis: Static/dynamic analysis (WinDbg, IDA Pro), x86_64/ARM64 assembly, symbol resolution, and binary patching/unpacking.
  • Anti-Tamper & Subversion Mechanisms: Analyzing and designing runtime execution isolation, inline hooking detection, anti-debugging, and memory integrity verification.

Collaborative Projects

  • UPGDSED — Universal PatchGuard and Driver Signature Enforcement Disable (Co-creator with @hfiref0x).
  • DrvMon — Advanced real-time kernel-mode driver monitoring utility (Created with @hfiref0x).

AI Observability

  • Noesis Tension — A telemetry-based diagnostic tool for analyzing internal behavioral regimes of large language models during inference.

Misc / Utilities

  • Poor Man's FROST Defense — Chrome OPFS RAM Mitigation.
  • LDASM64 — x86-64 / VEX / EVEX / XOP instruction length disassembler (maintenance port).
  • secrep — rebuilding sections in unpacked binaries.

Research & Publications


Historical Projects

  • Kernel Detective — Early anti-rootkit / kernel introspection framework (ARK-era tool)
  • proxy_dll — CRT initialization trick for hooking protected applications
  • ntdll.h — Clean, minimal Windows NT headers (when Windows.h became too heavy)
  • lin2lua_ct2_3 — Legacy Lineage II CT2.3 Lua Script control
  • bdo_extender — Archival snapshot of my BDO Client Extender
  • old site — Archived articles and notes from the original fyyre.net

Connect

  • Email: fyyre [at] fyyre [dot] net
  • Security: PGP Key
  • Open to serious technical collaborations in Windows Internals and reverse code engineering.

Pinned Loading

  1. hfiref0x/UPGDSED hfiref0x/UPGDSED Public archive

    Universal PatchGuard and Driver Signature Enforcement Disable

    C 874 263

  2. DrvMon DrvMon Public

    Advanced driver monitoring utility.

    C 217 55

  3. noesis-tension noesis-tension Public

    Telemetry-based taxonomy of how LLMs strain, drift, and hallucinate — measured from layer activations, attention, KV cache, and MoE routing.

    Python 2

  4. noesis noesis Public

    Noesis - A lightweight toolkit for inspecting transformer internals through residual traces, layer-wise drift metrics, and token-level activation deltas

    Python 4

  5. kerneldetective kerneldetective Public

    Kernel Detective

    C 154 72

  6. rce_ai_ml rce_ai_ml Public

    Thinking Like a Reverser About Neural Networks

    5 2