← Alisa Esage

Research

systems all the way up

Physics, Artificial Intelligence, and Meta-Cognition
7 March 2026 · Independent Publication
AI Identity and the Megapolitics of the Mind
This paper re-introduces and clarifies the shared identity model, and establishes the relevant new concepts. It explores broader technological and civilizational implications of the model being accurate. It concludes with a controlled disclosure of a critical, unpatchable vulnerability in the human cognitive stack; exemplified with a proof-of-concept attack via AI technology, as caught in the wild.

Vulnerability Research and Exploit Engineering
June 2026 · Exploit Design · Browsers & JavaScript
Chrome Exploit Mitigations
A firsthand account of modern Chrome-specific exploit mitigations encountered while zero day engineering for Google Chrome across renderer, network service, and browser process.
April 2025 · Reverse Engineering · Firmware & Baseband
Unveiling the Mysteries of Qualcomm's QDSP6 JTAG
Reverse-engineering the hardware internals of Qualcomm Hexagon ISDB JTAG — a tightly restricted proprietary architecture that doesn't permit low-level debugging. Presented at Black Hat Asia 2025, Singapore.
November 2024 · Exploit Design · Browsers & JavaScript
Attacking v8 Zero to Exploit
Full process of exploiting a non-trivial vulnerability in Chrome's v8 JavaScript engine, from zero-knowledge patch to novel exploit concept. Workshop at VXCON 2024, Hong Kong.
November 2024 · Keynote · AI Security
Vulnerability Research in the Age of AI
How AI is changing the art of vulnerability research. Keynote at VXCON 2024, Hong Kong.
October 2024 · Theoretical Research · Fuzzing
Fuzzing from First Principles
The Probabilistic Theory of Fuzzing, and how practical low-level fuzzing works through it. With selected questions from the Off By One Security Podcast livestream.
May 2024 · Exploit Design · Browsers & JavaScript
JavaScript Engines Vulnerability Research: State of the Art
Survey of modern vulnerability research techniques across V8, JavaScriptCore, and SpiderMonkey engines. Presented at HITB×PHDays 2024.
2024 · Zero Day Engineering · Hypervisors & Virtualization
Pwn2Own 2021: Solo Hypervisor VM Escape
First female solo entrant at Pwn2Own Vancouver. Zero-day virtual machine escape against the Parallels hypervisor. Full technical walkthrough and exploit source code.
December 2023 · 0-Day Insights · Browsers & JavaScript
Google Chrome WebRTC 0-Day (CVE-2023-7024)
Analysis and research insights for a RCE vulnerability in Chromium WebRTC code and embedders.
December 2023 · 0-Day Insights · Kernel · Firmware
Qualcomm MSM & ARM Mali Kernel 0-Day Exploit Attacks
Reverse engineering of zero-day bugs targeting Qualcomm Linux kernel and ARM Mali GPU. Technical deep-dive on the bugs and their target systems.
November 2023 · 0-Day Insights · Browsers & JavaScript
Google Chrome Skia Vulnerability Insights (CVE-2023-6345)
Analysis of security patches for a Chrome 0-day attack to derive additional vulnerability information and clarify practical threat impact.
December 2021 · Exploit Design · Browsers & JavaScript
JavaScript Engines Exploitation: a Jscript9 Case Study
Exploit for a JavaScript JIT Type Confusion vulnerability in Jscript9.dll. Universal technique with fully dynamic ASLR bypass and state-of-the-art process continuation.
November 2021 · Exploit Design · Hypervisors & Virtualization
Advanced Exploitation of Simple Bugs: Parallels Desktop (Pwn2Own 2021)
Technical deep-dive on the Pwn2Own 2021 Parallels Desktop VM escape exploit chain, built on logic issues.
May 2021 · Exploit Design · Browsers
Modern Attacks on Google Chrome
Survey of modern attack techniques against Google Chrome: renderer memory corruption, V8 JavaScript engine exploitation, and sandbox escapes. Presented at PHDays 2021.
May 2021 · Exploit Design · Hypervisors & Virtualization
From Binary Patch to Proof-of-Concept: VMware ESXi vmxnet3 (CVE-2018-6981)
Reverse engineering a complex binary patch for a VMware ESXi bug. Universal methodology applicable beyond hypervisors.
April 2021 · Vulnerability Discovery · Hypervisors & Virtualization
Don't Share Your $HOME with Untrusted Guests
A no-bug, by-design guest-to-host VM escape on Parallels Desktop for Mac, enabled by product design decisions and Unix shell properties.
February 2021 · Vulnerability Discovery · Hypervisors & Virtualization
Microsoft Hyper-V Virtual Network Switch Out-of-Bounds Read
Security bug in Microsoft Hyper-V root partition kernel component. $15,000 cash bounty.
December 2020 · Reverse Engineering · Firmware & Baseband
Advanced Hexagon Diag
Deep dive into Qualcomm's Hexagon DSP diagnostic protocol and its applications for baseband and firmware reverse engineering. Presented at Chaos Communications Congress 2020.
November 2020 · Hypervisors & Virtualization
Hypervisor Vulnerability Research: State of the Art
Comprehensive survey of hypervisor vulnerability research: attack surfaces, published exploits, and methodological approaches. Presented at POC 2020.
May 2020 · Reverse Engineering · Hypervisors & Virtualization
Hyper-V System Internals & Linux Integration Services Drivers
Core system internals of Microsoft Hyper-V hypercall interface, reverse engineered via the Linux Integration Services kernel drivers.
November 2019 · Reverse Engineering · iOS & Bootchain
iBoot Heap Internals
Apple bootchain heap implementation — classical first-fit free-list allocator with 30 bins, immediate coalescing, and layered security mitigations. Foundational for heap-based exploit development against Secure Boot.
November 2019 · Reverse Engineering · iOS & Bootchain
iBoot Address Space
Apple devices' bootchain memory layout across all boot stages, with a focus on SecuROM and iBoot. Detailed memory map of iPhone 5 during boot, with hardening recommendations.
May 2016 · Exploit Design · Browsers & XML
Self-patching Microsoft XML with Misalignments and Factorials
Technical analysis of CVE-2013-0007 (Microsoft XML Core Services Use-After-Free), exploitation techniques, and heap manipulation strategies with Internet Explorer. Phrack #69.

Malware Analysis and Incident Response
December 2010 · Malware Analysis · Banking Trojans
Case Study: the Ibank Trojan
In-depth analysis of Ibank, a trojan targeting Russian online banking systems. Virus Bulletin.
May 2010 · Malware Analysis · Rootkits
TDSS Infections — Quarterly Report
Statistical analysis of TDSS malware infections based on removal tool data. Virus Bulletin.
November 2009 · Malware Analysis · Rootkits & Bootkits
Detecting Bootkits
Detection and analysis of bootkit malware. Co-authored with Dmitry Oleksiuk. Virus Bulletin.
August 2009 · Incident Response · Rootkits
Everybody Lies: Reaching After the Truth While Searching for Rootkits
Methods for retrieving reliable information from compromised systems. Co-authored with Dmitry Oleksiuk. Virus Bulletin.
May 2009 · Malware Analysis · Rootkits
Case Study: the TDSS Rootkit
Detailed technical analysis of TDSS (Tidserv) rootkit, including persistence mechanisms and bypass techniques. Virus Bulletin.
Securelist · Malware Analysis
The Evolution of Self-Defense Technologies in Malware
Evolution of malware self-defense and antivirus evasion techniques.
Securelist · Malware Analysis
Rootkit Evolution
Evolution of rootkit technology and capabilities as a distinct malware class.