About

Who's behind this blog, and what to expect from it.

Hi, I'm Tiziano Marra, a security researcher focused on offensive security, Windows internals, and EDR evasion.

This blog is where I document what I learn. Every write-up is a distilled version of a research thread I've actually pulled on, not a rehash of a tweet or a summary of someone else's work. I publish it because I want the same kind of long, complete, no-hand-waving posts I wish I'd found when I started.

What you’ll find here

Deep technical write-ups

Long, thorough, heavy on code. The why behind a technique, not just the what.

CVE research

Vulnerabilities I've responsibly disclosed, with the underlying mechanics and PoCs where appropriate.

Red-team tradecraft

Callstack spoofing, indirect syscalls, Defender evasion. Tooling that goes beyond copy-paste.

Elsewhere

Spotted a mistake, want to discuss, or have a suggestion? Open an issue on the relevant GitHub repository.

Disclaimer