𝙁 𝙀 𝙇 𝙄 𝙓 π™ˆ (@felixm_pw) 's Twitter Profile
𝙁 𝙀 𝙇 𝙄 𝙓 π™ˆ

@felixm_pw

Senior Researcher @Secureworks

ID: 992634695333629954

linkhttp://felixm.pw calendar_today05-05-2018 05:18:48

1,1K Tweet

780 TakipΓ§i

471 Takip Edilen

𝙁 𝙀 𝙇 𝙄 𝙓 π™ˆ (@felixm_pw) 's Twitter Profile Photo

Just got linked this really awesome blog by VanVleet about Detection Data Models. This should be a valuable read for my Detection Engineering friends out there: medium.com/@vanvleet/impr…

eversinc33 🀍πŸ”ͺβ‹†ο½‘Λš ⋆ (@eversinc33) 's Twitter Profile Photo

Yesterday I finally finished part II of my anti rootkit evasion series, where I showcase some detections for driver "stomping", attack flawed implementations of my anti-rootkit, hide system threads via the PspCidTable and detect that as well. Enjoy! eversinc33.com/posts/anti-ant…

Soufiane (@s0ufi4n3) 's Twitter Profile Photo

The (Anti-)EDR Compendium EDR functionality and bypasses in 2024, with focus on undetected shellcode loader. blog.deeb.ch/posts/how-edr-…

𝙁 𝙀 𝙇 𝙄 𝙓 π™ˆ (@felixm_pw) 's Twitter Profile Photo

WatchMojo Presents: Top 5 APT 🀑 Moments of 2024 All that effort for initial access just to use sam save and vssadmin πŸ’€ volexity.com/blog/2024/11/2…

WatchMojo Presents: Top 5 APT 🀑 Moments of 2024

All that effort for initial access just to use sam save and vssadmin πŸ’€

volexity.com/blog/2024/11/2…
eversinc33 🀍πŸ”ͺβ‹†ο½‘Λš ⋆ (@eversinc33) 's Twitter Profile Photo

It doesnt have to be RISC-V :) Wrote a little MIPS I VM (based on a playstation emulator I started writing years ago) that can execute MIPS compiled modules without the need for allocating additional executable memory

It doesnt have to be RISC-V :) Wrote a little MIPS I VM (based on a playstation emulator I started writing years ago) that can execute MIPS compiled modules without the need for allocating additional executable memory
eversinc33 🀍πŸ”ͺβ‹†ο½‘Λš ⋆ (@eversinc33) 's Twitter Profile Photo

I just finished writing the final part of my anti-anti-rootkit series, where I do a slight twist on the .data ptr hijacking IPC method, to create a "threadless" rootkit, concluding the trilogy :) Enjoy. eversinc33.com/posts/anti-ant…

𝙁 𝙀 𝙇 𝙄 𝙓 π™ˆ (@felixm_pw) 's Twitter Profile Photo

This evening DebugPrivilege walked me through some case studies from the WinDBG section of his debugging fundamentals repo. Defiantly check it out and bookmark it! github.com/DebugPrivilege…

Octoberfest7 (@octoberfest73) 's Twitter Profile Photo

Really cool work in this blog. My answer to the Time Travel Debugging problem attached. Using timers (Ekko) for sleep, add an additional one to check if the TTDRecordCPI.dll is loaded; if so force the process to crash so implant is never unmasked during the trace.

Really cool work in this blog. My answer to the Time Travel Debugging problem attached. Using timers (Ekko) for sleep, add an additional one to check if the TTDRecordCPI.dll is loaded; if so force the process to crash so implant is never unmasked during the trace.
DebugPrivilege (@debugprivilege) 's Twitter Profile Photo

Ever tried VSS tracing? I’ve been using it to troubleshoot Volume Shadow Copy issues. It’s super useful but not widely known, so I wrote a quick blog post about it. medium.com/@Debugger/trou…

5pider (@c5pider) 's Twitter Profile Photo

Introducing Havoc Professional: A Lethal Presence We’re excited to share a first look at Havoc Professional, a next-generation, highly modular Command and Control framework, and Kaine-kit our fully Position Independent Code agent engineered for stealth! infinitycurve.org/blog/introduct…

𝙁 𝙀 𝙇 𝙄 𝙓 π™ˆ (@felixm_pw) 's Twitter Profile Photo

Question for people doing Windows dev on Macbooks. Are you using Azure VMs or are you using a physical NUC with Proxmox (etc). Curious what experiences people have had with both and which is recommended most 🧐