Skip to content
View overkazaf's full-sized avatar
🏠
Working from home
🏠
Working from home

Block or report overkazaf

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
overkazaf/README.md

Typing SVG


DRM Engineer at NetEase · Previously Alibaba Cloud

Blog GitHub followers Profile Views


0xaf@re-lab:~$ whoami

Security engineer. 10+ years reversing DRM systems, Android app protections, and low-level binary obfuscation. I break content protection stacks (Widevine · FairPlay · PlayReady), reverse mobile security at scale (MetaSec · MTGSig · SecurityGuard), and build offensive tooling that bridges static analysis and runtime instrumentation.

0xaf@re-lab:~$ cat /etc/career
BUAA → ECUST → Acxiom → Alibaba Cloud → NetEase (current)

0x00 Exploit Surface

┌─── DRM & Content Protection ───┐
│                                │
│  Widevine L1/L3                │
│  FairPlay + KSM                │
│  PlayReady SL3000              │
│  Netflix MSL Protocol          │
│  Chrome CDM Internals          │
│  Whitebox Crypto · HDCP        │
│                                │
└────────────────────────────────┘
┌─── Mobile Reverse Engineering ─┐
│                                │
│  Douyin MetaSec (6-god sigs)   │
│  Meituan MTGSig                │
│  Taobao SecurityGuard          │
│  PDD libpdd_secure             │
│  Xiaohongshu Shield            │
│  APK Hardening (24 vendors)    │
│                                │
└────────────────────────────────┘
┌─── Offensive Tooling ──────────┐
│                                │
│  Frida Instrumentation         │
│  Ghidra Scripting              │
│  OLLVM Deobfuscation           │
│  Symbolic Execution            │
│  Native VMP Analysis           │
│  unidbg Emulation              │
│                                │
└────────────────────────────────┘
┌─── Low-Level Systems ──────────┐
│                                │
│  ARM TrustZone (EL0→EL3)      │
│  TEE Security                  │
│  MITM Infrastructure           │
│  Device Fingerprinting         │
│  SVC Syscall Protection        │
│  eBPF Tracing                  │
│                                │
└────────────────────────────────┘

0x01 Featured Project

D810G

The most comprehensive open-source deobfuscation toolkit for Ghidra

Stars Tests Rules Arch Docs

┌─ D810G ──────────────────────────────────────────────────────────────┐
│                                                                      │
│  OLLVM/Tigress CFF Deflattening  ·  60 MBA Rules (Z3-verified)      │
│  Opaque Predicates (standard + number theory)  ·  BCF Removal        │
│  Dead Code Elimination  ·  String Decryption (XOR/RC4/multi-byte)    │
│  VM Devirtualization + Bytecode Tracing  ·  6-Pass Auto Pipeline     │
│  Standalone CLI + Interactive Editor  ·  Ghidra Plugin + Analyzer    │
│                                                                      │
│  $ d810g cli simplify "(x | y) - (x & y)"                           │
│    → (x ^ y)  [Z3 verified, rule: mba_xor_1]                        │
│                                                                      │
└──────────────────────────────────────────────────────────────────────┘

0x02 Arsenal

D810G

Ghidra deobfuscation framework. 201 tests,
60 MBA rules, OLLVM/Tigress/BCF/strings/VM.
Java plugin + Python engine + CLI.

Ponce4Ghidra

Symbolic execution plugin for Ghidra.
Taint analysis & constraint solving.

reverse_engineering

RE cookbook — DRM, Android native, exploitation
techniques, analysis workflows. The field manual.

aria

FairPlay DRM decrypt pipeline. KSM extraction,
stream decryption, m3u8 repackaging.

re-agent

AI-powered terminal agent for RE and CTF.
Go + LLM-driven binary analysis.

cap

MITM proxy for mobile RE. Go + Svelte.
Real-time traffic interception & analysis.

unpack

Android unpacker. 24 commercial packer vendors.
Automated deprotection pipeline.

sidecar

Rootless chroot launcher for FairPlay DRM
decrypt on Linux. User namespace, PTY, zero root.

0x03 Dispatches from the Lab

0xaf@re-lab:~$ tail -f /var/log/research.log
tag post date
re Ponce4Ghidra 符号执行实战 2026-10-03
hw 用 RP2350 从零搭建一个 DRM 系统 2026-09-30
re PDD libpdd_secure Anti-Token 2026-08-26
re 美团 MTGSig DFP Risk Control 2026-08-26
drm PlayReady SL3000 Deep Dive 2026-08-24
drm Widevine PSSH & L1 Deep Dive 2026-08-24

→ all 25 posts


0x04 Loadout

Go C Python Java JavaScript Svelte Bash

Ghidra Frida radare2 unidbg IDA Pro Unicorn Keystone Capstone Z3

Android Linux ARM Docker QEMU




github-snake

0xaf@re-lab:~$ echo $MOTTO
DRM systems don't break themselves.

Popular repositories Loading

  1. reverse_engineering reverse_engineering Public

    Reverse engineering cookbooks written by me, Gemini, and Claude Code.

    HTML 11 1

  2. aria aria Public

    Apple Music Lossless Audio Service — HTTP API for AAC and Hi-Res ALAC (24-bit/48kHz) download with FairPlay decrypt pipeline.

    Python 8 1

  3. re-agent re-agent Public

    A reverse engineering and CTF agent for the terminal: planner/executor/researcher routing, 24 local tools, workflow modes, and live turn visibility.

    Go 3 1

  4. blogs blogs Public

    Security research blog — DRM, Android RE, binary analysis

    HTML 1

  5. Ponce4Ghidra Ponce4Ghidra Public

    Interactive symbolic execution plugin for Ghidra, powered by angr + Z3. Solve constraints, crack passwords, reverse algorithms — right from the Ghidra UI.

    Python 1

  6. unpack unpack Public

    Android unpacker: scan → dump → repair → verify. 24 packer vendors, 3 engines (Memory/Frida/eBPF), DEX repair pipeline.

    Python 1 1