MSRC VULN-195458 · GHSA-g5r6-gv6m-f5jv · Sydney, Australia
George Wu — ADF Veteran, independent security researcher, Sydney. I reverse malware, document techniques, and share everything for free because no one else teaches this stuff without charging hundreds.
Self-funded. Built in personal time. Given away free.
If it helps you — that's the point.
Adversarial thinking applied towards defensive knowledge — reverse engineering live implants captured in the wild and learning Windows OS internals.
Building techniques from first principles to actually understand them. Every case study, analysis, and home-baked demo on this site comes from non-stop failure with no support or industry experience.
I do not know everything, I learnt backwards. Because I want to give other beginners a chance to understand at a fraction of the time.
Security tools and references - free and functional
Live security news aggregated from public sources
Real hacking isn't one binary that defeats every defender. It's a kill chain — a series of moves, each one building on the last. Initial access, persistence, privilege escalation, lateral movement, exfil. Most of what I document here is pieces of that chain. The defender only needs to catch one link. You need to get all of them right.
Documented attack techniques with video proof. Each links to a full writeup.
Tired of AI that won't explain offensive techniques?
Frontier models refuse to discuss exploit development, AV evasion, or real attack chains. My voice agent tutor is different — it's trained specifically on my research and speaks in cybersecurity context without the safeguards and rate limits.
Run it locally with your own ElevenLabs API key. No rate limits, no refusals, just my voice walking you through the material.
Voice agent app requires API key to authenticate my voice model.
Command reference with live variable substitution
22nd Survey Division is the independent security research practice of George Wu — ADF Veteran based in Sydney, Australia. Registered as Occupation Force Callsign GSW Pty Ltd.
CVE submissions, MSRC disclosures, responsible PoC documentation. Everything goes public after vendors patch. Code ships, not PDFs.
This site includes affiliate links to tools I actually use. When you sign up through these links, I may earn a commission at no extra cost to you. It helps keep the research free and the servers running.
Current partners: ElevenLabs
This work has a mentor — an Israeli security researcher and former IDF operator whose name stays private. He showed me what real work looks like. Soldier to soldier, that was enough.
My voice model is trained on all content here. Want it to explain concepts? You'll need an ElevenLabs API key — get one here →
"I want to go back to the fundamentals... What you've shared is worth far more than the amount I'm sending."
— @ismailjaweedahmed 10-year veteran"For exposing pedo scum. Fan of your work, keep going."
— hxpnctrpstr"For the children.. and also teach me c#nt"
— Qwenobi"I want to go back to the fundamentals... What you've shared is worth far more than the amount I'm sending."
— @ismailjaweedahmed 10-year veteran"For exposing pedo scum. Fan of your work, keep going."
— hxpnctrpstrThanks for reading.
This is what I do in my spare time. I'm not trying to sell you a course or become famous. I just think security knowledge shouldn't be gatekept behind expensive certifications. If this helped you, pass it on.