About

About Me

๐Ÿ‘‹ Hello, Iโ€™m Mahdi Hasanzadeh

AKA P4RAD0X โ€” Offensive Security Enthusiast, System Internals Researcher, and Red Team Practitioner.


๐Ÿง  The Offensive Mindset

I am deeply passionate about the art of breaking and bypassing. To me, offensive security is not just about running public exploits; itโ€™s about understanding the underlying logic of complex systems to find the one edge case that the developer never anticipated. I thrive on the constant cat-and-mouse game between attackers and defenders, where every new mitigation spawns a new bypass technique.

My goal is to bridge the gap between theoretical vulnerabilities and practical, weaponized exploits while sharing knowledge to make the infosec community stronger.


โš™๏ธ Deep Dive into System Internals

My true fascination lies far below the surface of user-mode applications. I am obsessed with system internals and spend countless hours dissecting:

  • The Windows NT Kernel: Exploring the Executive, Kernel-Mode drivers, and the Object Manager. I focus heavily on understanding undocumented structures, the inner workings of the Windows Registry, and how processes and threads are managed at the deepest level.
  • Linux Fundamentals: Analyzing the Linux kernelโ€™s process scheduler, memory mapping, and the VFS (Virtual File System) layer to understand how to manipulate these resources.
  • Binary & Memory Forensics: Reverse engineering PE (Portable Executable) and ELF binaries using tools like IDA Pro, Ghidra, and x64dbg. I enjoy unraveling packing algorithms, analyzing malware samples, and understanding how code behaves in memory.
  • Low-Level Interaction: Researching syscall tables, API hooking mechanisms (both user-mode and kernel-mode), and process injection techniques to fully grasp how operating systems handle core security primitives.

๐Ÿš€ Red Team Tradecrafts & Adversary Emulation

As a red team practitioner, I focus on emulating sophisticated adversaries to test organizational defenses. My area of expertise covers the entire attack lifecycle, with a heavy emphasis on operational security (OPSEC) and evasive tradecraft:

  • C2 (Command & Control) Development: Designing custom C2 frameworks that utilize diverse protocols (HTTPS, DNS, SMB) to blend into legitimate network traffic, employing asynchronous beaconing and dynamic agent profiling.
  • EDR & AV Evasion: Researching how Next-Gen AV and EDR solutions work (ETW, AMSI, Kernel Callbacks) to develop in-memory execution techniques, unhooking strategies, and sleep obfuscation to bypass signature and behavioral detections.
  • Active Directory Exploitation: Mastering Kerberos abuse (Golden/Silver Tickets, Kerberoasting, AS-REP Roasting), Pass-the-Hash, SMB relay attacks, and ACL misconfigurations to navigate complex domain environments stealthily.
  • Adversary Simulation: Mapping attack paths using tools like BloodHound and executing adversary emulation plans based on MITRE ATT&CK frameworks to assess detection and response capabilities.

๐Ÿ“ก Current Focus

Right now, I am actively researching:

  • Modern EDR kernel bypasses and the evolution of user-mode hooking.
  • Advanced persistence mechanisms that survive OS reinstallation.
  • Automating C2 infrastructure deployment with robust OPSEC in mind.

๐ŸŒ Letโ€™s Connect

I am always open to collaborating on research, sharing insights, or discussing the latest in red teaming. Feel free to reach out or check out my latest projects:

Stay curious, and hack the planet responsibly! ๐Ÿ›ก๏ธ