Ali Mohammad (Ahoura) Moharramzadeh
Security Researcher & ML Engineer
Iran
About
Security researcher and ML engineer. My security work centers on Windows internals, kernel-mode development, and offensive tooling — anti-cheat engines, EDR-evasion research, malware analysis, and vulnerability research submitted as CVEs. My engineering work is in C++, Rust, Python, and TypeScript, from kernel drivers up to the backend services around them.
As an ML Engineer I build, train, and ship models in production, and I bring the same low-level approach to the math and tooling underneath them. Most of my public work lives in my writing: exploit and vulnerability write-ups, ML research and tooling notes, and technical tutorials — published here and on YouTube.
Experience
ML Engineer — زروان داتس هوش دادە
2025 — presentBuilding and shipping machine-learning systems in production: data pipelines, model training and evaluation, and the services that serve them.
Writing
All posts →My main portfolio. Security research — exploits, vulnerability analysis, and CVE write-ups — alongside ML research, the math behind it, the tooling I build, and tutorials.
Education & Certifications
Certifications
- Red Team OperationsRavin Academy
- Malware DevelopmentMaldev Academy
- Advanced C++Anisa Group
- Python — Beginner to AdvancedMaktabkhooneh
Skills & Tooling
- Languages
- C++RustPythonJavaScript / TypeScript
- Security
- Windows internalskernel-mode developmentEDR evasionmalware developmentvulnerability research
- Offensive tooling
- MythicAdaptixC2MetasploitMimikatzBloodHoundWiresharkGoPhish
- ML & AI
- Model Context ProtocolLangGraphOllamaClaude CodeCodex
- Systems
- Windows SDK / WDKArch LinuxImGuiTauri
- Web
- Next.jsNestJSExpress.js
- Tooling
- GitDockerCI/CDn8nNeovim
Projects
Perca
C++ · Lua · Windows WDKKernel-mode anti-cheat engine. Detects DLL injection, unauthorized memory access, and signature-based tampering in online games, with a Lua layer for custom detection plugins.
pe-sentinel
C++ · PythonPE static analysis and packer detection. Fingerprints Windows binaries without executing them — section-level entropy scoring, heuristic packer detection, imphash clustering, JSON output for triage pipelines.
apiresolve
Python · IDAPython · x86-64IDA Pro plugin for obfuscated API and string resolution. Emulates hash-based import resolution to recover dynamically-loaded calls in stripped binaries, and decodes stack-constructed and XOR-encrypted strings in place.
Show 3 moreShow fewer
memscan
C++ · Python · WinDbgInjected-code detector for Windows memory dumps. Finds private RWX regions, unbacked executable pages, hollowed process images, and on-disk vs. in-memory header mismatches, then extracts them for static analysis.
ronitor
Rust · Actix WebHost telemetry service. REST API exposing process enumeration, loaded kernel modules, kernel logs, and network interface state for live host monitoring.
SVlogger
BashShell session alerting. Pushes a Discord/Telegram notification with geolocation, user, and TTY on every SSH login, for catching unauthorized server access.
pe-sentinel, apiresolve, and memscan are private while in active development — source available on request.
Contact
Open to security research and ML engineering opportunities. Reach me at ali@neox1de.com, or find me on GitHub, YouTube, and Telegram. My résumé is available as a PDF.