Grzegorz Tworek (@0gtweet) 's Twitter Profile
Grzegorz Tworek

@0gtweet

My own research, unless stated otherwise. Not necessarily "safe when taken as directed".
GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-

ID: 564509485

linkhttps://github.com/gtworek calendar_today27-04-2012 11:14:50

6,6K Tweet

32,32K Followers

1,1K Following

Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Does your famous-for-BSODs EDR block creation of IFEO\Utilman.exe Debugger entry? Create Debugger for IFEO\Utilman1.exe and rename the key... 😂

Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Phrack #71 Linenoise - "Master of Puppets - turning AV sandboxes into a botnet". What I can say... Honored and proud. Enjoy! phrack.org/issues/71/3.ht…

Phrack #71 Linenoise - "Master of Puppets - turning AV sandboxes into a botnet".
What I can say... Honored and proud. Enjoy! phrack.org/issues/71/3.ht…
Przemysław Kłys (@przemyslawklys) 's Twitter Profile Photo

If you're into #ActiveDirectory, keep it clean from stale objects. CleanupMonster, my new #PowerShell module, can help you with that. I wrote a blog post about it to make it easier to implement. It has fancy reporting and lots of customizations evotec.xyz/mastering-acti…

Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Yet another KVM on my desk 🙈 This time it's #NanoKVM Pros: tiny, fast, cheap, nice features. ❤️ Cons: no WiFi 👎 Thanks Rev for the tip!

Yet another KVM on my desk 🙈
This time it's #NanoKVM 
Pros: tiny, fast, cheap, nice features. ❤️
Cons: no WiFi 👎 
Thanks <a href="/RevToJa/">Rev</a> for the tip!
Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Finally releasing the tool! The Offline SAM Editor is here for IT pros, researchers, and security enthusiasts who want to access and edit SAM databases from offline OS disks. Source code included. Get your access: payments.gtworek.com/buy/54d82b09-4…

Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Poopowiadam (miejscami bezlitośnie) o Windows API. A w zasadzie o tym, jak kończy się staranie o zachowanie wstecznej zgodności przez kilkadziesiąt lat.

Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Newag (the company trying to sue hackers after they published information about drm backdoors found in trains) seems to fail with the narration as now they ask a court to make the hearing closed. Oops... 😅

Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Very informative "The Old New Thing" post about LUIDs: devblogs.microsoft.com/oldnewthing/20… And deeply inside AllocateLocallyUniqueId() is NtAllocateLocallyUniqueId() which in turns is an interlocked add. In current Windows versions it starts with 1001 and grows (quickly!) by 1.

Very informative "The Old New Thing" post about LUIDs: devblogs.microsoft.com/oldnewthing/20… 
And deeply inside AllocateLocallyUniqueId() is NtAllocateLocallyUniqueId() which in turns is an interlocked add. 
In current Windows versions it starts with 1001 and grows (quickly!) by 1.
Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Listing all processes keeping particular file open is not a trivial task but since Vista we have a special syscall parameter for such purpose. Microsoft says "reserved for system use" but I was brave enough to wrap it into PowerShell function. Enjoy! github.com/gtworek/PSBits…

Listing all processes keeping particular file open is not a trivial task but since Vista we have a special syscall parameter for such purpose. Microsoft says "reserved for system use" but I was brave enough to wrap it into PowerShell function. Enjoy! github.com/gtworek/PSBits…
Grzegorz Tworek (@0gtweet) 's Twitter Profile Photo

Volume creation time seems to be quite unpopular #DFIR artifact even if it may be useful in some scenarios. Not to mention sandbox detection... 😈 It's why I needed a tool for it. Enjoy the C source code and compiled exe, as usual: github.com/gtworek/PSBits…

Volume creation time seems to be quite unpopular #DFIR artifact even if it may be useful in some scenarios. Not to mention sandbox detection... 😈
It's why I needed a tool for it.
Enjoy the C source code and compiled exe, as usual: github.com/gtworek/PSBits…