eversinc33 ๐Ÿค๐Ÿ”ชโ‹†๏ฝกหš โ‹† (@eversinc33) 's Twitter Profile
eversinc33 ๐Ÿค๐Ÿ”ชโ‹†๏ฝกหš โ‹†

@eversinc33

computers be computin

ID: 1486678085239988224

linkhttps://eversinc33.com calendar_today27-01-2022 12:31:01

705 Tweet

4,4K Followers

978 Following

eversinc33 ๐Ÿค๐Ÿ”ชโ‹†๏ฝกหš โ‹† (@eversinc33) 's Twitter Profile Photo

If I had a penny for each time I get ducked by Nt/ZwAllocateVirtualMemory writing the rounded up page size into the RegionSize variable, which I then use later thinking it still had the original value, I could probably buy myself a copy of Windows Internals ๐Ÿคฎ

William R. Messmer (@wmessmer) 's Twitter Profile Photo

If you update WinDbg today (1.2504.15001.0), you might notice another icon in the View tab of the ribbon, one called "Parallel Stacks". While incredibly useful in its own right, this isn't just a parallel stacks view. It's the introduction of graph visualization for extensions!

If you update WinDbg today (1.2504.15001.0), you might notice another icon in the View tab of the ribbon, one called "Parallel Stacks".  While incredibly useful in its own right, this isn't just a parallel stacks view.  It's the introduction of graph visualization for extensions!
๐™ ๐™€ ๐™‡ ๐™„ ๐™“ ๐™ˆ (@felixm_pw) 's Twitter Profile Photo

With some guidance from DebugPrivilege I've found a way to easily dump clear text implants even while they sleep. Bad day for sleep obfuscation ๐Ÿ’ค blog.felixm.pw/rude_awakeningโ€ฆ

eversinc33 ๐Ÿค๐Ÿ”ชโ‹†๏ฝกหš โ‹† (@eversinc33) 's Twitter Profile Photo

Sunday project: Running a virtual machine in an OpenCL kernel/shader to execute arbitrary code on the GPU. API calls and host memory R/W still has to trap into the CPU of course, but a fun exercise in GPU malware :3

Sunday project: Running a virtual machine in an OpenCL kernel/shader to execute arbitrary code on the GPU. 

API calls and host memory R/W still has to trap into the CPU of course, but a fun exercise in GPU malware :3
Ido Veltzman (@idov31) 's Twitter Profile Photo

I'm happy to finally release NovaHypervisor! NovaHypervisor is a defensive hypervisor with the goal of protecting AV/EDR vendors and crucial kernel structures that are currently uncovered by VBS and PatchGuard. Full explanation below 1/6. github.com/Idov31/NovaHypโ€ฆ

eversinc33 ๐Ÿค๐Ÿ”ชโ‹†๏ฝกหš โ‹† (@eversinc33) 's Twitter Profile Photo

When the CTF challenge is hosted in korea and has a 5 second time limit for the solution, so you have to rent a VPS in japan to avoid the network bottleneck

eversinc33 ๐Ÿค๐Ÿ”ชโ‹†๏ฝกหš โ‹† (@eversinc33) 's Twitter Profile Photo

I was too lazy for disclosure, which is why I posted about it instead. Theres probably like a few hundred practically free CVEs for privesc for whoever wants to claim them in there :3

eversinc33 ๐Ÿค๐Ÿ”ชโ‹†๏ฝกหš โ‹† (@eversinc33) 's Twitter Profile Photo

As a little follow up, I wrote a small blog post/tutorial on how to reverse engineer windows drivers with IDA - this is aimed at people that newer touched drivers before and covers IOCTL codes, IRPs and some IDA shenanigans with unions. eversinc33.com/posts/driver-rโ€ฆ Enjoy :3

As a little follow up, I wrote a small blog post/tutorial on how to reverse engineer windows drivers with IDA - this is aimed at people that newer touched drivers before and covers IOCTL codes, IRPs and some IDA shenanigans with unions.

eversinc33.com/posts/driver-rโ€ฆ

Enjoy :3