R3dF09 (@r3df09) 's Twitter Profile
R3dF09

@r3df09

Pwn2Own2017 Edge Winner, MSRC MVR 2020. Member of @XuanwuLab EcoSec team. Windows/macOS/iOS. Tweets are my own.

ID: 1580671231

calendar_today09-07-2013 15:31:20

127 Tweet

2,2K Followers

324 Following

Jaron Bradley (@jbradley89) 's Twitter Profile Photo

TrueTree now has more reliability on macOS 11/12. This includes the ability to look "around" the RunningBoard service and acquire the true parent of a process. Thank you Objective-See Foundation for the code and the tips on the obscure ApplicationServices framework. themittenmac.com/tools/

Jiska (@naehrdine) 's Twitter Profile Photo

Just published a Frida tutorial, with a focus on iOS devices. It contains an introduction to Frida and iOS, low-level iOS interfaces (GCD, XPC, IOKit, Mach), and Objective-C instrumentation. youtube.com/watch?v=h070-Y… youtube.com/watch?v=qpEIRe… youtube.com/watch?v=x48y2e…

Just published a <a href="/fridadotre/">Frida</a> tutorial, with a focus on iOS devices. It contains an introduction to Frida and iOS, low-level iOS interfaces (GCD, XPC, IOKit, Mach), and Objective-C instrumentation.

youtube.com/watch?v=h070-Y…
youtube.com/watch?v=qpEIRe…
youtube.com/watch?v=x48y2e…
Justin Bui (@slyd0g) 's Twitter Profile Photo

Took some time recently to dive into in-memory Mach-O execution on macOS. I dig into the API calls necessary to perform reflective code loading, present my Swift implementation, cover nuances on Big Sur vs Monterey, and how to detect it on Monterey! slyd0g.medium.com/understanding-…

Minoru Kobayashi (@unkn0wnbit) 's Twitter Profile Photo

It took a while, but the English version of the macOS Forensics Hands-on Workshop materials are now available. Have fun! jsac.jpcert.or.jp/archive/2022/p… jsac.jpcert.or.jp/archive/2022/d… #DFIR #JSAC2022

Justin Bui (@slyd0g) 's Twitter Profile Photo

Updates to Apple's Endpoint Security Framework (ESF)! - Ability to mute events based on path/process - New `eslogger` binary to quickly get your hands dirty with ESF - More userland events! developer.apple.com/videos/play/ww…

Csaba Fitzl (@theevilbit) 's Twitter Profile Photo

I put together a quick blogpost about this new AMFI Launch Constraints mitigation, with examples what kind of exploits it prevents. Again this was long time needed. Well done to everyone involved! theevilbit.github.io/posts/amfi_lau…

Guilherme Rambo (@_inside) 's Twitter Profile Photo

As promised, my experimental virtualization app for Apple Silicon Macs is now open source. Here’s VirtualBuddy: github.com/insidegui/Virt…

Romain THOMAS (@rh0main) 's Twitter Profile Photo

I'm going to start a series of two blog posts related to iOS obfuscation. The first part will be about RASP on iOS like detecting the Frida's Stalker or using the iOS Sandbox to detect jailbroken devices. romainthomas.fr/post/22-08-ios…

Trung Nguyễn (@ntrung03) 's Twitter Profile Photo

iBoot running on QEMU? 🔥🌸 In case you missed our BH talk, here is one of the presented demo. The slides should be linked below. Meanwhile, our new DWC3 USB emulation and iOS 16 support is published, be sure to check it out at the repo. github.com/TrungNguyen190…

Ivan Krstić (@radian) 's Twitter Profile Photo

LIVE: Apple Security Research, our new blog and website at security.apple.com! We launch with an update on Apple Security Bounty (security.apple.com/blog/apple-sec…), and a deep dive into some fundamental XNU memory safety improvements with kalloc_type (security.apple.com/blog/towards-t…). Enjoy!

Impalabs (@the_impalabs) 's Twitter Profile Photo

Today we are releasing Hyperpom, a fuzzing framework for ARM64 binaries based on the Apple Silicon hypervisor. Check out our latest blogpost, as well as our GitHub repo, to learn more about the project and its internals. 📙 blog.impalabs.com/2211_hyperpom.… 🗃️ github.com/impalabs/hyper…

Today we are releasing Hyperpom, a fuzzing framework for ARM64 binaries based on the Apple Silicon hypervisor. Check out our latest blogpost, as well as our GitHub repo, to learn more about the project and its internals.

📙 blog.impalabs.com/2211_hyperpom.…
🗃️ github.com/impalabs/hyper…
Ivan Fratric 💙💛 (@ifsecure) 's Twitter Profile Photo

New Project Zero blog post in which I dissect Apple DER-encoded entitlements and tell a story about how I found a fun (albeit short-lived) bug in the way they were decoded. googleprojectzero.blogspot.com/2023/01/der-en…

Objective-See Foundation (@objective_see) 's Twitter Profile Photo

Stoked to announce "Objective by the Sea" (#OBTS) v6.0 🍎🧑🏻‍🏫🌴☀️ Details: 📍 Marbella, Spain 🗓️ Oct 9ᵗʰ - 13ᵗʰ '23 ℹ️ Hop over to the conf. site to sign up for trainings, conference, & book a room at the venue: objectivebythesea.org/v6/index.html Can't wait to see y'all at the there! 🥰

Brandon Dalton (@partyd0lphin) 's Twitter Profile Photo

Happy Friday everyone! Want a ProcMon for macOS? Ever wish you had your own Endpoint Security client you could task? Want to peer behind the macOS EDR curtain? Have a go and let us know what you think! github.com/redcanaryco/ma…

Jaron Bradley (@jbradley89) 's Twitter Profile Photo

We've released a new blog on an APT malware targeting macOS that we call RustBucket. The actor is using decoy PDF documents that act as a key when loaded within an attacker provided pdf app. The malware has three stages. Check out our writeup for details jamf.com/blog/bluenorof…

Ivan Krstić (@radian) 's Twitter Profile Photo

🔺New on the Apple Security Research blog: we pit our hardened kalloc_type XNU allocator against SockPuppet, a powerful vulnerability from the past: security.apple.com/blog/what-if-w…