me.c3

513 posts

me.c3

me.c3

@mec314

شامل ہوئے Eylül 2012
318 فالونگ49 فالوورز
me.c3
me.c3@mec314·
the developer helped to solve everything
English
0
0
0
29
me.c3 ری ٹویٹ کیا
Hex-Rays SA
Hex-Rays SA@HexRaysSA·
We are thrilled to announce the winners of the 2024 Hex-Rays Plugin Contest! 🥇1st Place: hrtng 🥈2nd Place: aiDAPal 🥉3rd Place: idalib Rust bindings Check out our reviews of the winners and other notable submissions here: eu1.hubs.ly/H0gRDRn0 Huge thank you to all participants for their innovative contributions. Your creativity continues to enhance the IDA community. #HexRays #IDAPro #PluginContest #ReverseEngineering
Hex-Rays SA tweet media
English
1
25
51
17.8K
me.c3 ری ٹویٹ کیا
Wietze
Wietze@Wietze·
🚀 Today I'm launching ArgFuscator: an open-source platform documenting command-line obfuscation tricks AND letting you generate your own 🔥 68 executables supported out of the box - use right away, make tweaks, or create your own 👉 Now available at argfuscator.net
English
20
184
674
61K
me.c3 ری ٹویٹ کیا
Joe Desimone
Joe Desimone@dez_·
Bypass AMSI by uninitializing the IActiceScript object (zero ptr at 0x3c8). Slightly modified wscript no longer calls into AMSI.
Joe Desimone tweet mediaJoe Desimone tweet mediaJoe Desimone tweet media
English
7
48
244
15.2K
me.c3 ری ٹویٹ کیا
x86matthew
x86matthew@x86matthew·
I created a hypervisor-based emulator for Windows x64 binaries. This project uses Windows Hypervisor Platform to build a virtualized user-mode environment, allowing syscalls and memory accesses to be logged or intercepted. elastic.co/security-labs/… Project: github.com/x86matthew/Win…
English
29
345
1.3K
112.5K
me.c3
me.c3@mec314·
@filip_dragovic try for another dir not C:\Config.Msi or with > medium IL
English
0
0
4
315
Filip Dragovic
Filip Dragovic@filip_dragovic·
Seems that new windows update bring some changes in NTFS as its no longer possible to delete folders with ::$INDEX_ALLOCATION allocation trick with DeleteFile api.
Filip Dragovic tweet media
English
6
39
209
20.1K
me.c3 ری ٹویٹ کیا
Duncan Ogilvie 🍍
Duncan Ogilvie 🍍@mrexodia·
DataExplorer is a plugin for @x64dbg that integrates the pattern language from @WerWolv's ImHex. You can quickly visualize data structures in memory!
Duncan Ogilvie 🍍 tweet mediaDuncan Ogilvie 🍍 tweet media
English
4
79
372
20.2K
me.c3 ری ٹویٹ کیا
sixtyvividtails
sixtyvividtails@sixtyvividtails·
Small gift for you! 🔺🟦🔺 Code to reliably stop almost any 3rd party Windows security system, via ci!CiValidateFileAsImageType. No privileges needed at all, user rights are enough. Shall work on most OS: 10 22H2, 11 24H2, WS2022. But: it requires CI policies (e.g. HVCI/UMCI on).
sixtyvividtails tweet media
English
7
76
383
32.2K
me.c3 ری ٹویٹ کیا
Stephan Berger
Stephan Berger@malmoeb·
"Raspberry Robin uses an interesting approach to avoid detection while adding registry data. Rather than modifying the Windows registry directly using common Windows API functions (e.g. RegOpenKey, RegSetValueEx), Raspberry Robin first renames the target registry key to a random one, writes the registry data into the renamed key, and renames it back to its original name. However, if administrator privileges are available, Raspberry Robin uses a different approach. At first, it renames the registry key, creates an offline registry hive in the Windows temporary directory with a random filename. Then, it writes the registry data in the offline registry hive and loads the offline hive to the global registry tree using ZwRestoreKey." zscaler.com/blogs/security…
English
1
17
64
6.7K
me.c3 ری ٹویٹ کیا
Eli
Eli@elikaski·
I wrote an article about known attacks on Elliptic Curve Cryptography, check it out! github.com/elikaski/ECC_A…
English
7
123
396
37K
me.c3
me.c3@mec314·
flareon serpentine.exe ?
Română
2
0
0
80
me.c3
me.c3@mec314·
@malcat4ever @joe4security does the option require a corporate tariff to the sandbox? no access to dumps on a free communitie account
English
1
0
0
38
Malcat dev
Malcat dev@malcat4ever·
TIL a new shortcut to download all process dumps in @joe4security. Very convenient to quickly unpack malware:
Malcat dev tweet media
English
1
0
9
798
me.c3 ری ٹویٹ کیا
sixtyvividtails
sixtyvividtails@sixtyvividtails·
You've coded brilliant fallback codepath for case when menacing 𝐁𝐞𝐞𝐩 EDR is running, but have no rights to check its presence? EZ check: isBeepEdrDriverRunning = NtQueryFullAttributesFile( ObjAttr(L"\\Driver\\Beep"), NtCurrentTeb()) == STATUS_OBJECT_TYPE_MISMATCH;
English
2
9
60
8.3K
me.c3
me.c3@mec314·
@TriggerMeHappy Stuck on level 5. What should i pay more attention to: the LZMA algorithm, RSA or download symbolic names for some additional libraries?
English
1
0
0
454
Maik Morgenstern
Maik Morgenstern@TriggerMeHappy·
Finished the first 5 challenges of #flareon11 and feeling already tired :D
Maik Morgenstern tweet media
English
3
0
16
2.8K