🎯 Happy 2026, Threat Hunters!
We compiled 12 battle-tested tips to hunt the unknown, no IOCs, just anomalies.
🔍 Windows/Linux
💥 Scaled to 10K+ endpoints
👉 https://t.co/PJkHLMdiGR
#ThreatHunting#Cybersecurity#DFIR#UnknownThreats
Exalyze 1.0 is out 🥳
What's new on it?
- Analysis pipeline rebuild for transparent updates
- Yara generation (opcodes) have been improved
- Pivots added for IP/domains to @virustotal@shodanhq@censysio@onyphe@fofabot
See you on https://t.co/OUYhNuNZLa
I'm glad to share my talk at @Botconf 2025!
Do you want to know how we compare a sample with 150k others in seconds on @Exalyze_io? This talk is made for you 🚀
At the end, you'll get a hint on what's coming next for Exalyze! 😉
https://t.co/ByVdJXGBTu
https://t.co/AVASoPQLrp
Good morning! Just published a blog post diving into Windows Kernel Pool internals: basics, memory allocation functions, internal structures, and how Segment Heap, LFH, and VS work.
https://t.co/2KlYba9gxc
🚀 Take your malware analysis skills to the next level with Exalyze
Discover our unique capabilities to compare malware code with our entire database, identifying similar samples and uncovering hidden connections.
👉 https://t.co/AVASoPQLrp
@Exalyze_io
Think HVCI and kCET mean the end of kernel code execution? I wrote a blogpost exploring an alternative way to execute a kernel payload! :)
https://t.co/Ty542HtdqL
Hey :)
If you missed your daily Frenglish dose, my talk about Octo at @virusbtn is now available on Youtube:
https://t.co/h6qRJ4QEYG
Talked about malware, infrastructure, bulletproof hoster, and more. The full paper is also available in the description :)
@teamcymru_S2
Slides & video from our @GrehackConf talk "Attacking Hypervisors - A Practical Case" are online! Learn how we exploited vulnerabilities to escape VirtualBox during Pwn2Own Vancouver 2024: https://t.co/c90C2pnmMa
In our search for new forensic artifacts at @ExaTrack, we sometimes deep dive into Windows Internals.
This one is about COM and interacting with remote objects using a custom python LRPC Client.
STUBborn: Activate and call DCOM objects without proxy: https://t.co/FKPocJRN2Z
So far, I have written 706 pages to help the security community. My goal will be writing new articles of the Exploiting Reversing Series (ERS), which is focused on security research. However, I am planning to write one or two additional articles of my previous series MAS (Malware Analysis Series) to finish it off.
10. https://t.co/6SNMK1u99L
09. https://t.co/YMTSBl5HLa
08. https://t.co/yvXoY9uWtf
07. https://t.co/DIcpSdRpfW
06. https://t.co/AvjPAaTmQN
05. https://t.co/4wFVoBGapZ
04. https://t.co/PE7JeEM5lm
03. https://t.co/QXa2To5Z4S
02. https://t.co/BPt9L7QFdW
01. https://t.co/vGnT26NOin
#windows #idapro #kerneldrivers #kernel #infosec #reversing #malwareanalysis #vulnerability #securecode
Excited to share my latest article: PgC - a novel approach to disable Patchguard during runtime using basic memory management principles.
It has worked against every version of Patchguard for the last 7 years, without needing any updates!
https://t.co/H5dDddpuMP