Skip to content
View sys0xFF's full-sized avatar

Highlights

  • Pro

Block or report sys0xFF

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sys0xFF/README.md

banner

Anthony Sforzin

Offensive security and vulnerability research — from application-level code to the kernel — with coordinated disclosure, reverse engineering, and fuzzing.

Software Engineering student & IT Support Intern @ FIAP (São Paulo)

I run Caustic — an independent security research lab. Vulnerability research and coordinated disclosure, from application code to kernel and firmware.

Selected work

  • CVE-2025-61155 — co-credited researcher (with Gabriel Maciel Ramos and Gabriel Gomes). Access-control flaw in a signed Windows kernel-mode driver (Hotta Studio, GameDriverX64.sys): an unprivileged IOCTL reaches ZwTerminateProcess in kernel context, allowing termination of arbitrary processes including protected security services (BYOVD / EDR-killer class). NVD: CWE-400 / CVSS 5.5. Subsequently weaponized in the wild by Interlock ransomware and documented by FortiGuard Labs and CyberPress.

Credentials

  • CRTA — Certified Red Team Analyst (CyberWarFare Labs)
  • NPP — Novo Pentest Profissional (Desec Security)

Elsewhere

Popular repositories Loading

  1. CVE-2025-61155 CVE-2025-61155 Public

    Forked from pollotherunner/CVE-2025-61155

    Official public advisory for CVE-2025-61155

    C++

  2. pagewright pagewright Public

    Design-grade SaaS landing pages, generated, not templated. A Claude Code skill.

    Python

  3. sys0xFF sys0xFF Public

    GitHub profile