Skip to content
CAI
Software that uses CAICheck a score

enkomio/Misc

38.5

Weak · 3 October 2026

980

lines of production code

F#

with C++

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This repository is a collection of low-level Windows security utilities and reverse engineering tools, primarily implemented in C++, F\#, and assembly. It provides capabilities for binary manipulation, such as embedding resources in PE files, and process manipulation, including debugger detection and process re-parenting. Additionally, it contains experimental code for process injection techniques, directory comparison utilities using fuzzy hashing, and solutions for algorithmic challenges and CTFs.

Features

Added CodeJam 2019 solutions for Foregone Solution, Cryptopangrams, and You Can Go Your Own Way

The CodeJam2019 directory now includes a Visual Studio solution containing three F\# projects: 'Foregone Solution', 'Cryptopangrams', and 'You Can Go Your Own Way'. Each project provides a console application targeting .NET Framework 4.7 that reads input from standard input and writes the solved output to standard output, implementing the respective algorithmic logic for these Google Code Jam 2019 problems.

CodeJam2019 · high confidence

Added CompareDirectory utility for comparing directory contents

A new command-line tool has been added that compares two directories and reports differences, including new files, files with different content hashes, and files that appear to have been moved (same hash, different name). The tool identifies differences by computing SHA-1 and ssdeep hashes for each file, using ssdeep similarity scores to detect near-duplicates or moved files, and outputs a summary and detailed list of discrepancies.

CompareDirectory · high confidence

Added HM0x14 CTF writeup solution code

The Hm0x14Writeup directory now contains the source code for a Hackmeeting 0x14 reversing challenge writeup. This includes a C++ implementation (hm0x14\_sol.cpp) that uses the Windows BCRYPT API and OpenMP for parallelized meet-in-the-middle key recovery, alongside a .NET F\# implementation (Program.fs, Encryption.fs, etc.) that performs similar DES/2DES encryption and key search operations. The entry also includes supporting files such as App.config, AssemblyInfo.fs, Storage.fs, Utility.fs, Test.fs, and a README.md.

Hm0x14Writeup · high confidence

Added Process Re-Parenting utility to spawn processes under Explorer

A new C application has been added that allows users to launch a specified executable as a child of Windows Explorer (explorer.exe) rather than the current parent process. By utilizing the PROC\_THREAD\_ATTRIBUTE\_PARENT\_PROCESS API, the tool re-parents the new process to the shell, which is useful for simulating remote process creation or ensuring the new process is managed by the desktop environment.

ProcessReParenting · high confidence

Added RoningLoader process injection technique implementation

A new C++ project has been added to demonstrate a process injection technique used by the RoningLoader malware. The implementation, located in CodeInjection/main.cpp, replicates the malware's method of injecting shellcode by leveraging Windows Thread Pool Wait Completion Packets and I/O completion ports. The solution includes the necessary Visual Studio project files and a README that references the original Elastic security analysis and SafeBreach's 'Pool Party' research.

CodeInjection · high confidence

Added WordsGenerator with recursive and iterative implementations

The WordsGenerator application has been added, providing two methods to generate all possible words (or passwords) from a given alphabet and length: a recursive approach in RecursiveGenerator.fs and an iterative approach in IterativeGenerator.fs. The Program.fs entry point demonstrates both by generating combinations using the 'ABCD' alphabet up to length 4, printing each result to the console.

WordsGenerator · high confidence

Added legacy Perl password generation scripts

The repository now includes two Perl scripts in the old\_stuff directory: bruteforce.pl, which generates all possible character combinations up to a certain length, and passwordg.pl, which generates passwords of a specified length using a defined alphabet. These tools are pre-2008 artifacts intended for local experimentation and do not affect current product functionality.

_old\stuff · high confidence

Initial repository structure and build system

Established the foundational project structure with the Misc.sln solution file, incorporating C++ projects (ProcessReParenting, CheckDebuggerCrossArchitecture), F\# projects (WordsGenerator, Hm0x14Writeup, CompareDirectory, AddResource), and the SsdeepNET third-party library. Added a FAKE-based build system (build.bat, build.fsx) for compiling and packaging, initialized the SsdeepNET submodule, and configured .gitignore and README.md with project documentation.

(repo-wide) · high confidence

New AddResource CLI tool for embedding binary resources into PE files

A new command-line utility has been added to the AddResource project, enabling users to embed or replace binary resources within PE (Portable Executable) files. Built in F\# and targeting .NET Framework 4.6.1, the tool uses Windows API calls (BeginUpdateResource, UpdateResource, EndUpdateResource) to modify PE binaries. Users can specify the target file, the resource file to add, and an optional resource name (defaulting to 'RES0'), with verbose logging available via the --verbose flag. This provides a programmatic way to inject custom data into executables without manual resource editing.

AddResource · high confidence

New tool to detect debuggers via cross-architecture PEB inspection

Added the CheckDebuggerCrossArchitecture project, an x86/x64 assembly utility that detects attached debuggers by executing 64-bit code from a 32-bit process (using 'Heaven's Gate') to read the \BeingDebugged\ flag directly from the PEB. The tool exits with code 1 if a debugger is present and 0 otherwise, providing a method to bypass simple flag-patching techniques.

CheckDebuggerCrossArchitecture · high confidence

Behavioural changes

Added SsdeepNET submodule

The repository now includes a new Git submodule for SsdeepNET, integrating external fuzzy hashing functionality into the project's third-party dependencies.

ThirdPart · high confidence

Documentation of Hex-Rays decompiler limitation with CMOVcc instructions

This change adds a README and assembly source code demonstrating a specific behavior in Hex-Rays decompiler v7.4.0.191112 where the generated pseudo-code may fail to show the invocation of a function (func\_b) called via a conditional move (CMOVcc) instruction, even though the code executes correctly. The entry clarifies that this is not a bug but a known decompilation limitation, and notes that specifying a custom calling convention can resolve the issue.

Hex-Rays · high confidence

Dependencies

Added F\# project files and package references for multiple utility and challenge solutions

Added .fsproj and packages.config files for several new F\# projects, including AddResource, CodeJam2019 solutions (Cryptopangrams, Foregone Solution, You Can Go Your Own Way), CompareDirectory, Hm0x14Writeup, and WordsGenerator. These projects target .NET Framework 4.6.1 or 4.7 and reference FSharp.Core (versions 4.5.2 or 4.7.0), System.ValueTuple (4.4.0), and additional packages like Argu (6.0.0), FSharpLog (2.2.0), and System.Configuration.ConfigurationManager (4.4.0) where applicable.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 38 → 38 (+0.0)
  • Rubric changed (rubric-2026.09.15 → rubric-2026.10.1) — scores are not directly comparable.

Lenses

  • Code Health 99 → 99 (+0.0)
  • Architecture 69 → 69 (+0.0)
  • Maturity 21 → 21 (+0.0)
  • Readiness 24 → 24 (+0.0)
  • Security 100 → 100 (+0.0)

Resolved (3)

  • Coverage not measured — no coverage collector is wired up
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

enkomio/Misc was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 3 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 77844e422ae5a04f78c042935cfd64abc9167e44 — the exact code this score is about.
  • Scored under rubric-2026.10.1 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-4f4226d619ea.