I've let my AI tools research all session logs (whether successful or failed) of the past year and let it destill a lessons-learned master reverse engineering skill. Here it is for you as well to enjoy:
https://t.co/dH4dzjKf1X
P.S.: There might a tool being spoiled which is tbr.
We're mostly an IDA shop at @CellebriteLabs, but I decided to play around with Ghidra. My main motivation was to experiment with agentic reverse engineering techniques. The result is an agent skill for Ghidra, which we are releasing publicly:
https://t.co/mPrNFR8mOq >>
DFIR analysts who use macOS as their daily driver deserve free and native forensic tooling. So I built one. 🍎
Introducing 𝗜𝗥𝗙𝗹𝗼𝘄 𝗧𝗶𝗺𝗲𝗹𝗶𝗻𝗲 — a timeline analysis app built from the ground up for Mac-based DFIR folks, forensic investigators, or SOC analysts. Built in appreciation of, and inspired by, Eric Zimmerman’s Timeline Explorer.
Every feature in this tool was shaped by real IR casework. Handling massive timelines, parsing artifacts here and there, and pivoting across logs during active investigations. I built IRFlow Timeline to be the native macOS timeline analyzer that actually keeps up with a live case. Every button and view is intentional; if it’s in the app, it’s because I needed it mid-case and realized the standard tools fell short.
No dependencies. Zero setup. Just drag, drop, and analyze.
#dfir #incidentresponse #timeline #macos #threathunitng #digitalforensics
MediaTek exploit that lets you write to arbitrary memory via the Download Agent, bypassing DA2 signature verification
https://t.co/jYc9aDbJYS
Blog post by @shomykohai#infosec
Just released a new tool that scans for Bluetooth devices including Bluetooth Low Energy (BLE) devices. It will scan for all, filtered by MAC, or if you have the Identity Resolving Keys (IRK), can be used to determine the Resolvable Private Address (RPA).
Works on MacOS, Windows, and Linux.
https://t.co/4ws9eSaZvn
#TrustedSec #BinaryDefense
Since Nothing decided to ignore my report, I decided to release it publicly.
You can find the source code and full details here: https://t.co/zHIwBEfaFG
It only supports the Nothing Phone 2a for now but it should apply to more MediaTek devices from what I've seen so far.
Android APK’s have a dedicated loader for Ghidra, but they’re also Archives with nested files which is a different loader. This causes quirks.
Here’s how to get around that and use the best tool.
Ghidra Is Best: Android Reverse Engineering https://t.co/X1h6doj9Nt