Kazuma Matsumoto

I work on offensive security and AI-assisted security research. I take systems apart to see how they work, and I write down what I find.

Most posts start from something I did not understand and could not find explained — a Windows mechanism, an edge case in a protocol, a trust boundary that a specification describes and the code does not enforce. Each post separates what I reproduced in a virtual machine from what is still a guess.

I am still learning, and this blog is where I keep the notes.

Interests

  • Windows internals
  • Linux internals
  • Reverse engineering
  • AI-assisted security research
  • Web application security

Disclosure policy

Every vulnerability is disclosed to the affected vendor before it is published here. Each post records the vendor’s response and its position on the finding. Any proof-of-concept code is provided for reproduction and defense — not for use against systems you do not own.