I'm Jimmy Mi (jm33), a security researcher who takes systems apart and then builds offensive tooling with what I learn. My work sits around C2 design, malware development, reverse engineering, and detection, and I'm happiest somewhere between a debugger and a packet capture.
I'm the creator of emp3r0r, an open-source command-and-control framework for Linux and Windows that I've been building since 2019. It's my main laboratory: a self-healing gossip-mesh C2 with assisted peer discovery, HTTP/2, QUIC, TOR and CDN transports, cross-platform BOFs, Starlark modules, and a stager built to leave as little behind as possible. I also maintain SSH-Harvester, mec, and windows-sandbox-init. Between them my projects have collected around 4k stars.
I write the whole process up at jm33.me. Recent posts cover Active Directory delegation attacks, weaponizing Starlark as a non-executable module layer, call stack spoofing, writing an ELF and BOF loader from scratch, and reverse engineering Go and Nim malware. The goal is always the same: start from "how does this actually work", end with code you can run, and be honest about the parts that don't.
Before that, I spent six years in security R&D at Topsec, working on malware detection, evasion, and incident response. I hold several patents on C2 and credential-harvesting techniques and a couple of CVEs, and I have a Master of Cybersecurity from Monash University, where my thesis was adversarial QUIC C2 camouflage against ML-based IDS and where I tutored the Software Security unit, plus a Master of Computer Science from ASU before that.
You can find me on GitHub, X, and LinkedIn. My GPG key is here.