Modern C2 implants use sleep masking & metamorphic code to stay hidden. We’re revealing how to unmask them using low-level runtime telemetry (ETW & CPU profiling) live in production including a POC with a lightweight sensor.
My team will be presenting our research at x33fcon:
https://t.co/qhtckSyxx5
The FLARE Learning Hub is launching with three modules:
- Malware Analysis Crash Course
- The Go Reverse Engineering Reference
- Introduction to Time Travel Debugging (TTD)
📟 Start learning: https://t.co/iw6SGpq9St
MICROSOFT BUILT A TOOL THAT CONVERTS LITERALLY ANYTHING INTO CLEAN MARKDOWN FOR YOUR LLM
pdfs. word docs. excel. powerpoint. audio. youtube urls
one pip install and your AI pipeline stops choking on raw files forever
no custom parsers. no broken layouts. no garbled text.
just clean, structured markdown your LLM can actually read
https://t.co/RSt0CczfYa
AV/EDR Lab Environment Setup
A curated list of various resources helpful in building own malware-centric research lab.
A post by Udayveer Singh (@m4lici0u5)
Source: https://t.co/ZM3A1n1zNQ
#redteam#blueteam#maldev#malwaredevelopment
Powershell for offensive security.
A list of offensive tactics with practical tips in using Powershell during security operations.
A post by Het Mehta (@hetmehtaa).
Source: https://t.co/HLQfIZEw4s
#redteam#blueteam#maldev#malwaredevelopment
Windows process internals - VADs (Virtual Address Descriptors).
A deep dive into VAD structures, their purpose and function, helpful in memory forensics.
A post by imp hash.
Source: https://t.co/QlN54Fa1lp
#redteam#blueteam#maldev#malwaredevelopment
🔓 Google/Mandiant released Net-NTLMv1 rainbow tables that enable cracking password hashes in under 12 hours using consumer hardware.
🔗 Learn more here → https://t.co/YNLx41xxJX