Pour notre première rump acceptée, @angel_killah nous parlera de reverse de jeu d'arcade dans sa rump "A practical example of how arcade games cheat you"
We are releasing a new method to collect the SRUM Windows forensic artifacts : https://t.co/LllcOTYvt8
@ExaTrack, we have discovered a new method to retrieve the database via a srumapi!SruQueryStatsEx.
Thus, we share this method that we used for 2 years in our tools.
🚀 Take your malware analysis skills to the next level with Exalyze
Discover our unique capabilities to compare malware code with our entire database, identifying similar samples and uncovering hidden connections.
👉 https://t.co/AVASoPQLrp
@Exalyze_io
🚨 WARNING: A fake domain—cff-explorer[.]com—has been registered to distribute malware. It currently appears as the top Google result when searching for "CFF Explorer". The only legitimate domain is https://t.co/p4MhOw9vZ5.
"A calculator app? Anyone could make that."
Not true.
A calculator should show you the result of the mathematical expression you entered. That's much, much harder than it sounds.
What I'm about to tell you is the greatest calculator app development story ever told.
For the first time, our training "Bug Hunting in Hypervisors" is open to the public at @reconmtl !
Designed for security researchers,we will dive into VM escapes, hypervisor attack surfaces, and real-world exploitation.
More info: https://t.co/Ngrjzu4Mun
The second part of my #WinDbg deep-dive into the #Windows#bootloader is up: Get ready for a decades-old registry structure, unique sorting algorithms, and lots of corner cases. The result is a modern Rust replacement for Mark Russinovich's LoadOrder tool: https://t.co/Xol8O32F6r
I wanted to know how WMI Win32_OperatingSystem.Caption get the correct Version number (ex: "Microsoft Windows 11 Pro").
Turns out it's a DLL export: winbrand!BrandingLoadString.
And there is a patent for that : https://t.co/DQznBaNEnt
After 6 years, I made a blog thingy again.
This time about MmScrubMemory. An innocuous looking function that has bitten my ass several times in the last several years. And if you're developing a hypervisor, it might've bitten yours, too.
https://t.co/9uEyjZPwVo
in today's 'no way, is it real?' we found out that Palo Alto's PAN-OS CVE-2024-0012 and CVE-2024-9474 were the equivalents of saying 'turn off auth and give me a shell'.
Enjoy!
https://t.co/P0PZq0diFF