About Me
๐ Hello, Iโm Mahdi Hasanzadeh
AKA P4RAD0X โ Offensive Security Enthusiast, System Internals Researcher, and Red Team Practitioner.
๐ง The Offensive Mindset
I am deeply passionate about the art of breaking and bypassing. To me, offensive security is not just about running public exploits; itโs about understanding the underlying logic of complex systems to find the one edge case that the developer never anticipated. I thrive on the constant cat-and-mouse game between attackers and defenders, where every new mitigation spawns a new bypass technique.
My goal is to bridge the gap between theoretical vulnerabilities and practical, weaponized exploits while sharing knowledge to make the infosec community stronger.
โ๏ธ Deep Dive into System Internals
My true fascination lies far below the surface of user-mode applications. I am obsessed with system internals and spend countless hours dissecting:
- The Windows NT Kernel: Exploring the Executive, Kernel-Mode drivers, and the Object Manager. I focus heavily on understanding undocumented structures, the inner workings of the Windows Registry, and how processes and threads are managed at the deepest level.
- Linux Fundamentals: Analyzing the Linux kernelโs process scheduler, memory mapping, and the VFS (Virtual File System) layer to understand how to manipulate these resources.
- Binary & Memory Forensics: Reverse engineering PE (Portable Executable) and ELF binaries using tools like IDA Pro, Ghidra, and x64dbg. I enjoy unraveling packing algorithms, analyzing malware samples, and understanding how code behaves in memory.
- Low-Level Interaction: Researching syscall tables, API hooking mechanisms (both user-mode and kernel-mode), and process injection techniques to fully grasp how operating systems handle core security primitives.
๐ Red Team Tradecrafts & Adversary Emulation
As a red team practitioner, I focus on emulating sophisticated adversaries to test organizational defenses. My area of expertise covers the entire attack lifecycle, with a heavy emphasis on operational security (OPSEC) and evasive tradecraft:
- C2 (Command & Control) Development: Designing custom C2 frameworks that utilize diverse protocols (HTTPS, DNS, SMB) to blend into legitimate network traffic, employing asynchronous beaconing and dynamic agent profiling.
- EDR & AV Evasion: Researching how Next-Gen AV and EDR solutions work (ETW, AMSI, Kernel Callbacks) to develop in-memory execution techniques, unhooking strategies, and sleep obfuscation to bypass signature and behavioral detections.
- Active Directory Exploitation: Mastering Kerberos abuse (Golden/Silver Tickets, Kerberoasting, AS-REP Roasting), Pass-the-Hash, SMB relay attacks, and ACL misconfigurations to navigate complex domain environments stealthily.
- Adversary Simulation: Mapping attack paths using tools like BloodHound and executing adversary emulation plans based on MITRE ATT&CK frameworks to assess detection and response capabilities.
๐ก Current Focus
Right now, I am actively researching:
- Modern EDR kernel bypasses and the evolution of user-mode hooking.
- Advanced persistence mechanisms that survive OS reinstallation.
- Automating C2 infrastructure deployment with robust OPSEC in mind.
๐ Letโs Connect
I am always open to collaborating on research, sharing insights, or discussing the latest in red teaming. Feel free to reach out or check out my latest projects:
- GitHub: github.com/yourusername
Stay curious, and hack the planet responsibly! ๐ก๏ธ