Eloi Benoist-Vanderbeken (@elvanderb) 's Twitter Profile
Eloi Benoist-Vanderbeken

@elvanderb

Enthusiast reverse engineer of obfuscated and protected binaries. Exploit things @Synacktiv. Very occasionally on twitter.

ID: 330386527

calendar_today06-07-2011 14:59:31

2,2K Tweet

4,4K Followers

285 Following

Synacktiv (@synacktiv) 's Twitter Profile Photo

A few months ago, the FreeBSD Foundation appointed us to audit two #FreeBSD critical components: the Bhyve hypervisor and the Capsicum sandboxing framework. Today, related advisories and patches have come out 🧵 1. Multiple vulnerabilities in libnv freebsd.org/security/advis…

Synacktiv (@synacktiv) 's Twitter Profile Photo

Octoscan, our GitHub actions vulnerability scanner, is now available as a GitHub action! It will find vulnerabilities in new commits and pull requests, and upload it to GitHub as it now supports the SARIF file format! github.com/synacktiv/acti…

Eloi Benoist-Vanderbeken (@elvanderb) 's Twitter Profile Photo

Better late than never... My Hexacon 2023 slides for "Finding and Exploiting an Old XNU Logic Bug" and the exploit code (WITH THE ANIMATED ASCII ART 🥷🔪🍎!!!) are up synacktiv.com/sites/default/… / github.com/synacktiv/CVE-…

Synacktiv (@synacktiv) 's Twitter Profile Photo

The 2025 training season is here! 🚀 Join our best ninjas for 5-day sessions on pentesting, reverse-engineering, and forensics (in French). Check out all the dates and topics on our website: synacktiv.com/offres/formati…

WineRump (@winerump) 's Twitter Profile Photo

Save the date, la seconde édition de #WineRump aura lieu: 🗓️ le vendredi 26/09/2025 📍à Bordeaux #WineRump c'est une conférence de cybersécurité avec des rumps, du vin et du jus de raisin dans une guinguette

Save the date, la seconde édition de #WineRump aura lieu:

🗓️ le vendredi 26/09/2025
📍à Bordeaux

#WineRump c'est une conférence de cybersécurité avec des rumps, du vin et du jus de raisin dans une guinguette
Synacktiv (@synacktiv) 's Twitter Profile Photo

Hunters International RaaS group has claimed 280+ victims since Oct 2023. Check out our latest blog post on the TTPs they use, including SMOKEDHAM malvertising & ESXi ransomware with advanced obfuscation. #RaaS #CyberSecurity #ThreatAnalysis synacktiv.com/en/publication…

Synacktiv (@synacktiv) 's Twitter Profile Photo

PagedOut! #6 magazine is out! This edition features two articles from our ninjas: - Implicit Unicode behaviors in database string functions - Calling Rust from Python: A story of bindings Dive into their insights here: pagedout.institute

Synacktiv (@synacktiv) 's Twitter Profile Photo

In iOS 18.4, Apple introduced a bug in dynamic symbol resolutions for some specific exports. F4b took a long journey down a rabbit hole to understand its root cause. synacktiv.com/en/publication…

Synacktiv (@synacktiv) 's Twitter Profile Photo

The "Objective-C helper" IDA plugin presented during the Sthack talk "Demystifying Objective-C internals" given by vic is now publicly available on GitHub at github.com/synacktiv/objc… The slides are also available on our website: synacktiv.com/sites/default/…

Eloi Benoist-Vanderbeken (@elvanderb) 's Twitter Profile Photo

If you are planning to learn about iOS, don't miss this training. Quentin and Etienne are exceptional researchers. No CVE ≠ no 0-days 😉😇

Synacktiv (@synacktiv) 's Twitter Profile Photo

🚨 Still a few days to register for our Azure Intrusion for Red Teamers training at #BHUSA! Very hands-on, full kill chain from zero to Global Admin with stealth in mind. Secure your seat now! blackhat.com/us-25/training…

🚨 Still a few days to register for our Azure Intrusion for Red Teamers training at #BHUSA! Very hands-on, full kill chain from zero to Global Admin with stealth in mind. Secure your seat now! blackhat.com/us-25/training…
Synacktiv (@synacktiv) 's Twitter Profile Photo

While performing security research on IoT control applications, Areizen and Cyp discovered critical vulnerabilities in the mobile app for the Eachine E58 drone. These flaws could potentially lead to remote code execution on the user's smartphone. synacktiv.com/en/publication…

Synacktiv (@synacktiv) 's Twitter Profile Photo

Ever thought your kitchen appliance could harbor a persistent threat? We reverse-engineered the Thermomix TM5 and uncovered vulnerabilities allowing arbitrary code execution, persistence, and secure boot bypass. Discover our step-by-step breakdown! synacktiv.com/en/publication…

Synacktiv (@synacktiv) 's Twitter Profile Photo

🚨 Still a few seats left for our iOS for Security Engineers training at #HEXACON2025! 4‑day hands-on labs to explore the iOS ecosystem and prepare for vulnerability research. 📍 Paris, Oct 6‑9 ➡️ hexacon.fr/trainer/meffre…

Eloi Benoist-Vanderbeken (@elvanderb) 's Twitter Profile Photo

Not their best picture but definitely THE best hands-on iOS training! Come and see for yourself how Etienne and Quentin master iOS! ⚠️ Warning, risk of massive skills overflow ⚠️

Synacktiv (@synacktiv) 's Twitter Profile Photo

That's a wrap on our Azure Intrusion for Red Teamers training at #BHUSA! 4 intense days from zero to Global Admin via Entra ID, M365, resources, DevOps, Intune & more 🔥 Huge thanks to all our participants and next stop: #HEXACON2025, Paris, Oct 6 🇫🇷

That's a wrap on our Azure Intrusion for Red Teamers training at #BHUSA! 4 intense days from zero to Global Admin via Entra ID, M365, resources, DevOps, Intune & more 🔥 Huge thanks to all our participants and next stop: #HEXACON2025, Paris, Oct 6 🇫🇷
Synacktiv (@synacktiv) 's Twitter Profile Photo

🔥 A few hours ago our experts took the stage at #DEFCON33, sharing cutting-edge research on SCCM exploitation and modern GPO attacks in Active Directory. Proud of the team! 🙌 cc kalimero Quentin Roland Wil

🔥 A few hours ago our experts took the stage at #DEFCON33, sharing cutting-edge research on SCCM exploitation and modern GPO attacks in Active Directory. Proud of the team! 🙌 cc <a href="/kalimer0x00/">kalimero</a> <a href="/quent0x1/">Quentin Roland</a> <a href="/wil_fri3d/">Wil</a>