Windows & Linux internals · Binary analysis
konkeri
Small, sharp tools for the layer between source code and the running process.
Rust C++ C Python
01About
I'm konkeri, an independent researcher working on systems programming and binary analysis across Windows and Linux. Most of what I build is small, focused tooling that makes the layer between source code and the running process visible: how compilers lay out objects and emit metadata, how linkers assemble a binary, how loaders map it into memory, and how debuggers and unwinders read it back.
I'm most interested in the metadata a compiler has to leave in a binary, such as RTTI, vtables, unwind tables and import tables. It survives stripping, and it often reveals more about a program's structure than the symbol table did.
Windows x64 internals
PE/COFF layout, the MSVC C++ ABI, RTTI and class hierarchy recovery, vtables, imports and exports.
Linux internals
ELF, the System V AMD64 ABI, DWARF call frame information and
.eh_frame, program headers and the loader.Reverse engineering tooling
Static analysis that recovers structure from stripped binaries, built to fit into Ghidra, GDB, x64dbg and WinDbg workflows.
Languages
C++ for Windows tooling, Rust for cross-platform CLIs, C for the lowest layers, Python for analysis scripts and test harnesses.
02Toolbox
- Languages
- Rust · C++17/20 · C · Python
- Platforms
- Windows · Linux
- Build
- CMake · Cargo · MSVC · MinGW-w64 · GCC · Clang / LLD
- Analysis
- Ghidra · x64dbg · WinDbg · GDB · readelf / objdump
- Formats & ABIs
- PE/COFF · ELF · DWARF CFI · MSVC C++ ABI · System V AMD64 · Microsoft x64
03Projects
Every tool is open source, tested in CI on Windows, Linux and macOS, and has zero third-party dependencies. This list is read live from GitHub.
04Release history
Every tagged release across the toolkit, newest first.
05How I work
Lab-first
Everything is built and tested on my own machines, against my own target binaries.
Verified, not eyeballed
Golden-file tests against real binaries, cross-checked with independent decoders such as readelf and llvm-readobj.
Small and auditable
Focused codebases with zero third-party dependencies, so the whole tool fits in your head.
Documented internals
Every README explains the format being parsed, with diagrams built from real data.
06Contact
The best way to reach me is on GitHub: open an issue on any of the repositories, or follow along there.