Most people learn security research by reading finished writeups. This one shows the actual process.
The messy, organic, step-by-step reality of reversing an unknown Windows mitigation from scratch. WinDbg. IDA. Hex Rays. Guard page violations. Trap flags. Zero prior knowledge of the target.
If you want to learn how to actually approach unknown Windows internals, start here.
https://t.co/Xq8xbSnG75
Author: @yarden_shafir
#ReverseEngineering #WindowsInternals #InfoSec
My Windows reverse engineering and exploit research workflow has been:
1. Pick a binary to research like tcpip.sys
2. Use https://t.co/fOxBB6tEsN to automate seeing existing binary versions, download, and generate diffs from them
3. Load the resulting .binexport's and .bindiff into an LLM and ask it to analyze
4. Look up the build number of previous Windows version that old binary existed in from https://t.co/U788ndiJbj such as 26100.8328 and create a VM from it
5. Write code and test, working backwards from LLM analysis
🚨 Nightmare Eclipse just released another vulnerability called MiniPlasma
GitHub: https://t.co/oySBY1X8ke
CVE: CVE-2020-17103 which is a high-severity elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver that allows an attacker to gain elevated, unauthorized access to a targeted system
morphkatz - Polymorphic PE rewriter for Windows x64 , rewrites binaries into semantically identical but byte-different variants https://t.co/FvYcpCVSqF
DeadMatter
Extracts LSASS credentials from memory dumps. Lightweight. Can be used to bypass AV/EDR. Usually is paired with DumpIt as both of them don't need GUI.
Tested with Microsoft Defender and Kaspersky
https://t.co/phV5wNPfBZ
@three_cube@_aircorridor#edr#apt #redteam
15-stage Windows malware development & analysis course in Rust. Red team builds it, blue team detects it. All 15 binaries achieved 0/76 on VirusTotal. https://t.co/Ggah7Lfaxk
AirTouch from @hackthebox_eu is a wireless box featuring SNMP enumeration, WPA2-PSK capture and crack, WireShark traffic decryption, client-side cookie role bypass with a phtml upload, and an evil twin via eaphammer to capture a crackable challenge.
https://t.co/JwFMChHBBJ
💪 Practical Reverse Engineering with IDA Pro
This tutorial showcases the typical workflow from ideation, to debugger, to IDA Pro to Visual Studio. Use these practical steps to build a functional project from scratch.
👉 https://t.co/LrIzbxKSrY
Releasing GodPotatoBOF: Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. OPSEC safe alternative to the .NET version. Based on the original GodPotato PoC by BeichenDream.
https://t.co/T1Cey2GZ4h
Do you want a collection of cybersecurity courses covering bug bounty, pentesting and cybersecurity in general?
https://t.co/HjsLE5OHSk
For just 33 euro's you can be the owner of this, all you need to grow from 0 to hero in weeks and not months or years.
I have coached over 15 people to report a bug and over 40 have attributed their success partially to me - so join the hype and see what it is about, no risk - full refund if requested no questions asked.