Colton Skees

36 posts

Colton Skees

Colton Skees

@ColtonSkees

Reverse Engineer

Katılım Ağustos 2021
62 Takip Edilen258 Takipçiler
Richard Johnson
Richard Johnson@richinseattle·
@ColtonSkees @spendergrsec @dodo_sec Yea this VMDragonSlayer is completely broken and never worked. The taint tracking is hardcoding TAINT_NONE and wacky hardcoded size limits even if it did work. No shadow memory, logging would be totally unoptimized.. hell the recursive path creation function isn’t even correct.
Richard Johnson tweet mediaRichard Johnson tweet mediaRichard Johnson tweet media
English
2
5
22
4.7K
Colton Skees retweetledi
vx-underground
vx-underground@vxunderground·
Lots of frustration in the malware analysis and reverse engineering community. It's been discovered a DEFCON talk, presentation, and the code which coincided with it, was AI slop. The talk itself had hallucinated terminology which (apparently) no one at DEFCON noticed. Bad.
vx-underground tweet media
English
73
166
3.3K
154.8K
Colton Skees retweetledi
Tim Blazytko
Tim Blazytko@mr_phrazer·
Happy to announce that @nicolodev and I will be giving a talk titled "Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications" at @reconmtl More information will follow in the coming days.
REcon@reconmtl

@mr_phrazer and @nicolodev will be presenting about Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications at Recon Montreal recon.cx more info to come soon!

English
1
7
32
10.4K
Colton Skees retweetledi
rev.ng
rev.ng@_revng·
🔴 We're at @DVConEurope! See you at today's presentation, 16.15, Forum 7. If you can't attend, here's our engineering paper: rev.ng/downloads/dvco…
rev.ng tweet media
English
0
9
45
3.3K
Colton Skees
Colton Skees@ColtonSkees·
(2) Notably it's implemented almost entirely in C#, with managed bindings for Remill, Souper, and LLVM. It was originally intended for breaking software protectors (blog post coming about this at some point), but later repurposed.
English
0
0
6
795
Colton Skees
Colton Skees@ColtonSkees·
(1) Decided to release the source code for my LLVM-based static binary analysis framework (github.com/Colton1skees/D…). It implements, among other things, an iterative control flow graph reconstruction algorithm heavily inspired by SATURN, using Remill and Souper.
English
3
52
203
21K
Colton Skees
Colton Skees@ColtonSkees·
The latest few updates introduce support for high degree polynomial MBAs Example:
Colton Skees tweet media
English
1
1
9
314
Colton Skees retweetledi
Matteo
Matteo@fvrmatteo·
@ColtonSkees and I have been playing with the algorithms part of "Efficient Normalized Reduction and Generation of Equivalent Multivariate Binary Polynomials" by @arnaugamez et al. (@ciphernyx) providing C# (fast) and Python (matching the pseudocode) implementations. Links below.
English
2
4
10
1.8K