h4vox@local:~$ ./render --profile --verbose[ok]

Havox

security researcher & tool builder

I study how Windows behaves underneath the documented API surface, reverse the parts that matter, and turn that understanding into tooling for adversary emulation and sharper detections.

status: open to research collaboration · uptime: coffee-driven

5+

research tools shipped

2

active builds

4

published notes

hours in a debugger

01

About

Offense informs defense.

Self-taught, starting from Windows internals and malware analysis and moving outward into reverse engineering and offensive tooling. Everything offensive stays inside authorized labs, purple-team engagements, and simulation work.

The work runs on two rails: building realistic adversary emulation capability, and feeding what that exposes back into detection engineering — EDR implementation, review and testing on one side; YARA, YARA-L and KQL rule work, log pipelines and threat hunting on the other.

Detection and telemetry work spans Google SecOps, Microsoft Sentinel and the Elastic Stack, with Windows and endpoint data as the centre of gravity, plus Azure and Active Directory simulation for identity-side coverage.

Focus areas

  • Adversary Emulation / Simulation
  • Threat Hunting
  • Detection Engineering (YARA / YARA-L / KQL)
  • Reverse Engineering
  • Windows Internals
  • Exploit Development Research
  • Custom Tooling & Loaders
  • EDR: implementation, review, testing
  • SIEM: Google SecOps, Sentinel, Elastic
  • Log pipelines & endpoint telemetry
  • Azure / Active Directory
  • IaC + AI-assisted automation
  • Agentic SOC experiments
02

Stack

Tools that show up in the daily loop.

Languages

  • C / C++
  • C#
  • Python
  • PowerShell
  • Assembly (x64)

Offensive

  • Cobalt Strike
  • Sliver
  • Havoc
  • Custom loaders
  • MITRE ATT&CK

Defensive

  • YARA / YARA-L
  • KQL
  • Sigma
  • Velociraptor
  • Sysmon / ETW

Platforms

  • Google SecOps
  • Microsoft Sentinel
  • Elastic
  • Azure / AD
  • Windows

$ ./contact --init

Building something adversarial or defensive?

Always up for research collaboration, detection work, or breaking down a technique until it stops being magic.