Bruce Dang
@brucedang
Chief Gardener at Veramine. Previously at Microsoft. author of Practical Reverse Engineering.
ID: 183349800
https://www.veramine.com 26-08-2010 19:55:26
388 Tweet
4,4K Takipçi
1,1K Takip Edilen
I am offering a public session of my Windows Kernel Rootkits class in January 2019 in Laurel, Maryland (JHU-APL campus). Last year we analyzed and implemented some of Equation Group's kernel implants; maybe we will do another group this year. More info at gracefulbits.regfox.com/windows-kernel…
tbh, I didn't want to publish it, but since someone is pushing me out of my comfort zone (meh! :P), you will probably have some news from me in the following days. :-^ Meanwhile, Thaís (@[email protected]) and I wrote a massive "thank you" post for Bruce Dang here: blackhoodie.re/Recon_mtl/
I've now open sourced my latest hypervisor written in C. github.com/gamozolabs/fal… . See it in action youtube.com/watch?v=AqFMSI… ! This is what I demoed to Bruce Dang way back at Recon 2016 and he thought it was pretty cool, so it must be.
Windows Kernel Rootkits: Techniques and Analysis by Bruce Dang offensivecon.org/trainings/2019…
[BLOG] Playing with the Windows Notification Facility (WNF) blog.quarkslab.com/playing-with-t… cc Gwaby Alex Ionescu Bruce Dang
There are many reasons to read Windows Internals end-to-end, but the most exciting one is attending Bruce Dang's Windows Kernel Rootkits training in offensivecon, one month from today. And I even get to be in the con with Dana Baril 😍 Thank you Blackhoodie so much!
Bruce Dang’s course is one of the best I’ve had the chance to attend.
Philip Tsukerman Bruce Dang has a really great rootkits training!
Motivated by a question from a friend and his coworker, I wrote a blog about HyperV and exit dispatching. See gracefulbits.com/2019/03/25/som… cc Saar Amar Arthur "Gerhart" Khudyaev Dmytro Oleksiuk 💥 [email protected] Also, Satoshi Tanda and I are offering a course on hypervisor development! See gracefulbits.regfox.com/designing-and-…
If you are interested in developing hypervisors as UEFI modules, MiniVisor is for you: github.com/tandasat/MiniV… Also Bruce Dang and I are offering a 5-day class on the development of hypervisor, including UEFI version, in October. See details at gracefulbits.regfox.com/hypervisor-dev…
I wrote up what I learned to design and develop the type-1 (UEFI-based) hypervisor. This should be helpful to explore MiniVisor's and other type-1 hypervisor's code base, especially for those who know about blue-pill style hypervisors but not type-1. standa-note.blogspot.com/2020/03/introd…
About 2 years ago, I and Bruce Dang had to spend a lot of time researching how to set up DCI (ie, HW debugger) for our class. Now we have inexpensive, off-the-shelf boards and software with webinars and guides for it. Amazing contributions to researchers by Alan Sguigna's team