mattless_

80 posts

mattless_

mattless_

@mattless_

security researcher && low-level dev

Italy Katılım Nisan 2017
769 Takip Edilen109 Takipçiler
mattless_ retweetledi
Objective-See Foundation
Objective-See Foundation@objective_see·
Just published our (8th) annual: "The Mac Malware of <Year>" white paper: objective-see.org/blog/blog_0x77… It's a technical deep dive into every new macOS malware specimen of 2023, detailing: 💉 Infection 💾 Persistence 📡 Capabilities ...plus samples, detections, & more! 👾🍎💻
English
2
107
218
46K
mattless_
mattless_@mattless_·
@zodiacon Not a full book, but some idea for chapters might be RPC, ALPC, DCOM, performance analysis
English
0
0
1
104
Pavel Yosifovich
Pavel Yosifovich@zodiacon·
As "Windows Kernel Programming, second edition" is essentially done, any requests for a book that you think may be missing in the Windows low-level/security/API/etc. space?
English
28
29
192
54.2K
mattless_ retweetledi
Windows On Windows
Windows On Windows@wowstartsnow·
Microsoft ○ く|)へ 〉  ̄ ̄┗┓ Windows 7 & 8.1 ┗┓  ヾ○シ    ┗┓ ヘ/       ┗┓ノ           ┗┓
日本語
15
69
470
22.1K
Kevin Naughton Jr.
Kevin Naughton Jr.@KevinNaughtonJr·
my typical day at Google as a software engineer: - get stuck on something - open an internal doc to get help - read first paragraph and open 3 other docs that are linked to - start reading 2nd doc's first paragraph and open 7 more internal doc links - cry
English
231
332
6.8K
720.4K
mattless_
mattless_@mattless_·
Got my copy!
mattless_ tweet media
English
0
0
0
0
mattless_ retweetledi
Daniele Cono D'Elia
Daniele Cono D'Elia@dcdelia·
@lcavallaro & I are thrilled to announce “Benefits and Outlook of Program Analysis for Systems Security”. This COSE special issue seeks technical & vision papers capitalizing on the rich cross-pollination ongoing among Computer Security, PL, and SE research. RTs appreciated! ▶️🧵
English
2
20
26
0
mattless_ retweetledi
Nasreddine Bencherchali
Nasreddine Bencherchali@nas_bench·
The "PCW.debugreport.xml" file inside %localappdata%\Diagnostics and %localappdata%\ElevatedDiagnostics (for elevated instances) is generated when executing the #follina thingy and it contains the payload. Maybe good for #dfir Did anyone look into this?
Nasreddine Bencherchali tweet media
English
3
81
234
0
mattless_ retweetledi
Paolo Stagno (VoidSec)
Paolo Stagno (VoidSec)@Void_Sec·
This blog post sums up my yearlong Windows Drivers research, detailing my own methodology for reverse engineering drivers, finding possible vulnerabilities, and understanding their exploitability: voidsec.com/windows-driver…
English
17
340
811
0
mattless_ retweetledi
Und3rf10w
Und3rf10w@Und3rf10w·
Some time ago, I wrote a proof-of-concept implant framework called Shlyuz that took some design cues from the CIA Assassin implant framework as described in #vault7. I'm happy to finally be able to share it with the world; but first, some background: und3rf10w.github.io/posts/2022/01/…
English
4
98
265
0
mattless_
mattless_@mattless_·
linux: “everything is a file” windows: “everything is a COM object”
English
0
0
1
0
mattless_
mattless_@mattless_·
Such a marvelous conf. An icebreaker opportunity for me since it was my first time as a speaker. If you are curious go take a look at our talk. @dcdelia
No Hat Con@nohatcon

⚠️Talks recordings available on our YT channel youtube.com/playlist?list=… Thanks again to all our speakers for making #nohat2021 such great event! @embyte @daviddiaul @gannimo @fabsx00 @ursachec @EranShimony @OcamRazr @LimitedResults @dcdelia @mattless_ @hookgab @Kapellmann @FlUxIuS

English
0
0
5
0
mattless_ retweetledi
Michael Gillespie
Michael Gillespie@demonslay335·
💡 Bit of advice for #ransomware devs... Use SetFilePointerEx, 🛑 NOT 🛑 SetFilePointer. Don't be like AvosLocker, who fuck up tons of data in the middle of 4GB+ files because they ignore the high move value and return... Pays to read the damn documentation. 📚
English
5
34
151
0