01About
I'm konkeri, an independent researcher working on systems programming and binary analysis across Windows and Linux.
Most of what I build is small, focused tooling that makes the layer between source code and the running process visible: how compilers lay out objects and emit metadata, how linkers assemble a binary, how loaders map it into memory, and how debuggers and unwinders read it back.
The metadata a compiler has to leave in a binary, such as RTTI, vtables, unwind tables and import tables, survives stripping. It often says more about a program's structure than the symbol table did.
- Windows x64
- PE/COFF layout, the MSVC C++ ABI, RTTI and class hierarchy recovery, vtables, imports and exports.
- Linux
- ELF, the System V AMD64 ABI, DWARF call frame information and
.eh_frame, program headers and the loader.
- Tooling
- Static analysis that recovers structure from stripped binaries, built to sit alongside Ghidra, GDB, x64dbg and WinDbg.
- Languages
- C++ for Windows tooling, Rust for cross-platform CLIs, C for the lowest layers, Python for analysis scripts and test harnesses.