KTM_POCS
Reports and proof-of-concept code for two vulnerabilities in the Windows Kernel Transaction Manager driver, tm.sys.
Personal research index · Singapore
Security Researcher
Published research, conference talks, tools, and field notes.
Press Enter to continue
Profile · Bearer
Jael Koh is a security researcher based in Singapore. His public work spans Windows internals, reverse engineering, and exploit development.
In 2025, Jael presented Windows Kernel Transaction Manager research with Cedric Halbronn at POC (opens in a new tab) and OffensiveCon (opens in a new tab).
Research · Records
Published repositories and technical work, presented as a ledger—not as fictional achievements.
Reports and proof-of-concept code for two vulnerabilities in the Windows Kernel Transaction Manager driver, tm.sys.
A Windows enumeration script for OSEP and a Python exploit template for OSED workflows.
Inspection notes · R / 01
Jael found and reported two use-after-free vulnerabilities in tm.sys. The public repository contains both reports and the demonstration code used at OffensiveCon25.
Inspection notes · R / 02
OSEP_enum.ps1 automates common Windows host-enumeration checks. OSED_exploit.py helps assemble and disassemble shellcode, construct ROP chains, and identify bad characters.
The repository does not declare a reuse license. Review the source terms before adapting the code.
Talks · Signals
Two presentations tracing the same Windows Kernel Transaction Manager research with Cedric Halbronn.
Lessons learnt from new vulnerabilities, presented by Cedric Halbronn and Jael Koh.
Windows 11 KTM vulnerabilities and the challenge of baking working exploits for them.
Signal notes · T / 01
A POC 2025 presentation in which Cedric Halbronn and Jael Koh revisit their Windows 11 Kernel Transaction Manager research and the lessons it produced.
Signal notes · T / 02
The joint presentation follows the discovery of two use-after-free vulnerabilities in Windows KTM and the challenges of exploiting them on Windows 11.
Writing · Archive
Long-form notes on security learning, exploit development, training, and a web CTF challenge.
W / 01 · 2025 archive
A retrospective on preparing for and earning OSEE, attending live training and conferences, beginning independent Windows research, and reflecting on the journey.
Read the essay (opens in a new tab)W / 02 · 2024 archive
A detailed first-year retrospective covering the learning path, exam experiences, tools, and lessons involved.
Read the essay (opens in a new tab)W / 03 · Web CTF
A technical write-up on recursively signing Flask session cookies to satisfy an SMT-backed math constraint.
Read the write-up (opens in a new tab)W / 04 · Schedule archive
An archived tracker updated 15 January 2025. Its listed sessions are from 2025; consult the source links for current availability.
Open the archive (opens in a new tab)Contact · Dispatch
Read longer notes on the blog, view public code on GitHub, or follow Jael’s professional profile and updates.
No hidden form or invented inbox—each route below goes directly to a public profile.