Stephen Fewer is a Senior Principal Security Researcher based in Ireland with over 20 years of hands-on experience locating and exploiting software vulnerabilities. He has deep expertise in reverse engineering, developer tooling, and offensive security techniques, contributing notable open-source work such as ReflectiveDLLInjection and browser fuzzing tooling used to automate crash management. A long-time contributor to Metasploit payloads, he has implemented low-level reflective DLL injection and privilege-escalation features that improved portability across architectures, including ARM/Windows RT. Stephen founded Relyze Software and has blended independent research with product-focused security engineering at Rapid7, demonstrating both entrepreneurial and enterprise impact. He’s known for pragmatic bug-fixing and performance-minded backend work—often fixing subtle pointer/relocation and crash-reporting issues that make security tools more robust. His career combines offensive research rigor with practical tooling that helps defenders and red-teamers alike.
20 years of coding experience
20 years of employment as a software developer
Associate's degree Software Development, Associate's degree Software Development at Coláiste Stiofáin Naofa
Grinder is a system to automate the fuzzing of web browsers and the management of a large number of crashes.
Role in this project:
Back-end Developer
Contributions:120 commits, 3 PRs, 9 pushes in 4 years 8 months
Contributions summary:Stephen primarily contributed to fixing bugs within the `grinder` project, focusing on areas such as browser fuzzing automation and crash management. These fixes involved modifications to JavaScript logging, debugging routines, and the handling of crash data. Additionally, the user implemented database updates to improve performance and fix issues in the crash reports. The user's work focused on maintaining and improving the core functionality of the system.
Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.
Role in this project:
Security Engineer
Contributions:12 commits, 2 comments in 2 years 4 months
Contributions summary:Stephen primarily focused on enhancing the reflective DLL injection technique. Their work involved modifying the reflective loader to support Windows RT (ARM) architecture, including adding ARM relocation support. They also addressed a pointer truncation bug and optimized the code by managing compiler inlining to prevent unexpected behavior. The user's contributions directly improved the portability and robustness of the reflective DLL injection tool.
memoryhostdubdll-injectioninjection
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.