- Demystifying DMGs - trying to make sense of the DMG file format, while working on HFSleuth
- DYLD Detayled - The internals of DYLD, the dynamic linker, and the __LINKEDIT section
- No Pressure, mon - Memory Pressure and MemoryStatus/Jetsam in OS X and iOS
- An Evening with Mobile Obliterator - The entitlements model of iOS
- GCD Internals - Grand Central Dispatcher
- Notes from the 8.0/10.10 DP 9.0/11.0 10/10.12 12/10.14
- The Annotated (informal) Guide to TaiG - Part 1 and 2
- Taking apart iOS OTA updates and The followup and the finale. and .. it continues.. and on... ... and on.. to the fateful conclusion
- Apple80211, reversed and reborn
- Guess-talt
- TaiG 2 Jailbreak analysis and Part II
- Circumventing task_for_pid using processor_set APIs
- Open sourcing launchd and libXPC, one binary at a time
- Notes from TvOS 9.0
- Under the Bridge(OS)
- AFC decomposed
- Make Debugging Great Again
- Casa de P(a)P(e)L