Tyler Holmwood

8 posts

Tyler Holmwood banner
Tyler Holmwood

Tyler Holmwood

@tyholms

Security Researcher @originhq

เข้าร่วม Temmuz 2025
124 กำลังติดตาม28 ผู้ติดตาม
Tyler Holmwood
Tyler Holmwood@tyholms·
My research from last week on Claude Code's Remote Control protocol has landed in the latest release of Praxis C2 framework - try it out for yourself now! github.com/originsec/prax…
English
0
2
6
427
Tyler Holmwood รีทวีตแล้ว
Origin
Origin@originhq·
Process argument spoofing has focused on modifying the PEB before a suspended process resumes. @jdu2600 traces what happens after and finds the initialization timeline has its own injection windows - ones that fire after the allow decision has already been made. originhq.com/blog/post-star…
English
0
22
44
6.7K
Tyler Holmwood รีทวีตแล้ว
Origin
Origin@originhq·
Claude's Chrome extension lets the agent interact with the web on your behalf. We reverse engineered it and found those same capabilities are exposed to any attacker on the endpoint, turning a productivity tool into a browser takeover primitive. originhq.com/blog/claude-fo…
English
0
13
34
2.1K
Tyler Holmwood รีทวีตแล้ว
Origin
Origin@originhq·
Windows Insider builds now have a native, OS-level broker for MCP servers. We reverse engineered Odr.exe to understand how it validates clients, manages consent, and controls access - uncovering undocumented COM interfaces and a full ETW audit trail. originhq.com/blog/msft-odr-…
English
2
25
58
5.7K
Tyler Holmwood รีทวีตแล้ว
Origin
Origin@originhq·
Computer use agents like Claude Code are transforming endpoint interactions for humans - and potentially attackers too. Today, we're releasing cua-kit: a post-exploitation toolkit to explore their offensive security implications. originhq.com/blog/cua-kit-a…
English
2
7
14
4.2K
Tyler Holmwood รีทวีตแล้ว
Origin
Origin@originhq·
While testing our agent against malware observed in the wild, we detected a LockBit encryptor not via file signatures or static IOCs, but by observing out-of-context execution of private memory using hardware telemetry. 🧵
English
1
8
31
6K