Process Explorer has no driver file in its directory. It embeds the driver, and the 64-bit variant, as custom PE resources inside its own binary. Here's how that works: https://t.co/OiTrhB4UGZ
New #macOS#Stealer in pure #Rust 🦀
🤦♂️ Dev forgot to strip TOML defaults from __const:
-- author = "SysAdmin Team"
-- service_name = "com.sysmonitor.agent"
🧬 Crate: sysmonitor::services::{grabber,searcher,tdata,telegram,keylogger}
🧱 Tokio + rustls + native LevelDB
💼 Targets corporate infra → .terraform .kube .helm .azure .docker
🐌 Playing the long game → grabber waits 24h before re-collecting
🤿 Deeper dive: https://t.co/Z6HOCE5MSd
pyghidra-mcp v0.2.0 is out with new --gui mode. 👀
Your local LLM drives a real Ghidra CodeBrowser, not a plugin.
New blog post shows firmware RE of the CVE-2024-3273 RCE chain with Gemma4.
https://t.co/8ShfEIraXY
I pushed v2.0 of my macOS Persistence Cheatsheet:
https://t.co/tNtFHiHKxS
It’s more than a cheatsheet now: 49 mechanisms, acquisition guidance, source-of-truth notes, collection/triage commands, triggers, review points, and clickable refs.
Binary Ninja 5.3 (Jotunheim) is released: https://t.co/jfRRcNRbYI
Major highlights: NDS32 support, AArch64 ILP32 ABI, new Universal MachO UI, command palette upgrade, new type library helpers, ghidra export, updated IDB import, HW and conditional breakpoints, and much more!
Tired of unzipping your password-protected malware samples just to analyze them? We've got you covered.
Our latest blog post covers Container Transforms and how Binja now handles nested binary formats with structure and provenance intact.
Read it here: https://t.co/mZvQl2OkZz
Apple (copied BlockBlock 👀) and added ClickFix protections… but kept the good stuff private 😤
Reversed xprotectd to see how it really works and emerged with enough detail to build your own (kinda)!
Read: No Paste for You!
https://t.co/hoWodAY53h
The FLARE team now freely distributes its quality reverse engineering and malware analysis educational content at https://t.co/bGCIjBfD3C. Launched with:
- Malware Analysis Crash Course
- Go Reversing Reference
- Intro to TTD
LevelBlue SpiderLabs profiles MioLab, a Mac MaaS advertised on Russian-language forums. The platform offers C2 & API integrations, with a strong focus on crypto theft including an add-on module built to target Ledger & Trezor hardware wallets. https://t.co/hevIwdn3wq