Fabien J.

3K posts

Fabien J.

Fabien J.

@zirkkam

Security Consultant & Hacker

Paris Katılım Temmuz 2013
239 Takip Edilen180 Takipçiler
Fabien J. retweetledi
littlelailo
littlelailo@littlelailo·
Had a lot of fun reversing Coruna over the last couple weeks and decided it would be worth to write it all up before I forget - so enjoy :) littlelailo.github.io/writeups/corun…
English
4
90
272
47.1K
Fabien J. retweetledi
Nicolas Krassas
Nicolas Krassas@Dinosn·
15-stage Windows malware development & analysis course in Rust. Red team builds it, blue team detects it. All 15 binaries achieved 0/76 on VirusTotal. github.com/F2u0a0d3/goodb…
English
1
71
350
17.8K
Fabien J. retweetledi
Nicolas Krassas
Nicolas Krassas@Dinosn·
Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows kernel drivers for exploitable IOCTLs natively using AI agents. github.com/416rehman/Deep…
English
2
96
426
20.3K
Fabien J. retweetledi
allthingsida
allthingsida@allthingsida·
I've been building libghidra: a typed SDK for automating Ghidra from C++, Python, and Rust (mainly for AI agents). Decompile, rename, comment, inspect symbols/types/xrefs, save, close, and reopen projects from code. Treat Ghidra like infrastructure, not just a GUI. Under the hood this is a typed API surface over a Ghidra host/extension. The same core workflows exist across C++, Python, and Rust, so you can use it for quick scripts, larger pipelines, or native tooling. 1/n
allthingsida tweet mediaallthingsida tweet mediaallthingsida tweet media
English
4
60
521
31.9K
Fabien J. retweetledi
blackorbird
blackorbird@blackorbird·
Illuminating VoidLink: Technical analysis of the VoidLink rootkit framework Analysis of the leaked rootkit source code complements those findings by providing a deep technical look at the kernel-level subsystem that underpins VoidLink's concealment capabilities. elastic.co/de/security-la…
blackorbird tweet media
blackorbird@blackorbird

New threat actor, UAT-9921, leverages VoidLink framework in campaigns blog.talosintelligence.com/voidlink/ Deconstructing Voidlink: Why New AI and Cloud-Native Threats Require a New Class of Defense isovalent.com/blog/post/void…

English
1
10
37
6.3K
Fabien J. retweetledi
Boris Larin
Boris Larin@oct0xor·
We analyzed the Coruna exploit kit and found intriguing code overlaps with Operation Triangulation. Full analysis on our blog: link below.
Boris Larin tweet media
English
4
88
431
38.3K
Fabien J. retweetledi
flux
flux@0xfluxsec·
This is awesome to see @Microsoft publish - "RustTraining". The link is in the comment below - check it out!! Just a small selection of cool things that caught my eye: - Production Async - Concurrency & Runtime - Why C/C++ Developers Need Rust - no_std — Rust Without the Standard Library - The Case for Rust for C# Developers - Systems & Production - Unsafe Rust - Controlled Danger - Phantom Types - Protocol State Machines And lots lots more.. going to spend some time going through this, looks like they have put a lot of work into it!
flux tweet mediaflux tweet mediaflux tweet mediaflux tweet media
English
9
70
478
31.1K
Fabien J. retweetledi
8kSec
8kSec@8kSec·
In this blog from our Mobile Malware series breaks down Xenomorph, an Android banking trojan that loads its DEX payload via JNI, bypassing standard DexClassLoader to evade hooks. Tools: JADX, Simplify, Medusa (Frida), Ghidra 8ksec.io/mobile-malware…
8kSec tweet media
English
0
19
61
3.8K