Nir Yehoshua

@NirYeho

Reverse Engineering, Malware Research, Memory Forensics, Incident Response and Windows Internals. Co-Founder of

 
Vrijeme pridruživanja: listopad 2016.

Tweetovi

Blokirali ste korisnika/cu @NirYeho

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @NirYeho

  1. Prikvačeni tweet
    25. stu 2019.

    Want to classify process injection by Windows API calls? Check out the new poster made by and me!

    Poništi
  2. 3. velj

    Now the link leads to the regular NSA site

    Prikaži ovu nit
    Poništi
  3. 3. velj
    Prikaži ovu nit
    Poništi
  4. proslijedio/la je Tweet
    2. velj

    How to create fake traffic jams in Google Maps with bucket full of smartphones Different perspective: 1) Buy mobile bots 2) Spoof GPS location 3) Control traffic

    Poništi
  5. proslijedio/la je Tweet
    1. velj

    When you are unpacking malware and the payload gets surprised.

    Poništi
  6. proslijedio/la je Tweet

    I found a new place to think about malware.

    Poništi
  7. proslijedio/la je Tweet
    26. sij

    Continuing to move the game forward . Much respect my brother 💪🏾 #33644

    Poništi
  8. proslijedio/la je Tweet
    25. sij

    Memhunter - Live Hunting Of Code Injection Techniques

    Poništi
  9. proslijedio/la je Tweet
    24. sij

    Maybe Group Use topics about Hamas to attack areas like Palestine ITW:4653916d821f58fcf9dde8c2c5e05a0c( إعلان رئاسي مرتقب بحل السلطة .docx) d077e2a0c58d0486c793bfe5ea81aaa5(هنية سيقيم في الخارج و حماس تصعد في غزة.pdf) Use Enigma to protect against malicious payload

    Prikaži ovu nit
    Poništi
  10. proslijedio/la je Tweet
    22. sij

    ppldump : Injects MiniDumpWriteDump() Shellcode into PPL procs (lsass demo) to dump memory. Got better tools, so useless to me now. Note sometimes the threads lock after the APC is queued, causing MiniDumpWriteDump to fail. Just resume the thread(s)

    Poništi
  11. 18. sij
    Poništi
  12. proslijedio/la je Tweet
    17. sij

    If you have AppLocker deployed, be aware that most times when Windows 10 is updated/upgraded, it creates a TASKS_MIGRATED folder under C:\windows\system32 that has the CREATOR OWNER, meaning that users can create and execute files from the folder and bypassing AppLocker 😱

    Prikaži ovu nit
    Poništi
  13. proslijedio/la je Tweet
    17. sij

    Want to make service removal really fun? Create a service with a unicode name. The service will run but won't show in sc.exe, services.msc, or taskmgr.exe and will sometimes cause a critical error while trying to find it with PowerShell/WMI. Unicode wins again.🤦‍♂️

    Prikaži ovu nit
    Poništi
  14. proslijedio/la je Tweet
    18. sij

    Just finished writing my second windows kernel Practical Reverse Engineering solution: "Dumping DPC Queues: Adventures in HIGH_LEVEL IRQL" 🥳 Writing signatures for undocumented windows kernel stuff in HIGH_LEVEL IRQL sure is fun (BSODs are also fun)😎

    Poništi
  15. proslijedio/la je Tweet
    17. sij
    Poništi
  16. proslijedio/la je Tweet
    17. sij

    Vulnerability severity levels

    Poništi
  17. proslijedio/la je Tweet
    16. sij

    After a lot of work and some crypto-related delays, I couldn't be more proud to publish 's and mine latest research - The complete overview of CET internals on Windows (so far!):

    Poništi
  18. proslijedio/la je Tweet
    16. sij

    Interesting Indicator about CVE-2020-0601 samples found. Certificate Date-Stamp older than Compiler Date-Stamp.

    Poništi
  19. proslijedio/la je Tweet
    16. sij

    Citrix NetScaler RCE vulnerability (CVE-2019-19781) scanning activity detected in the last 24 hours: New unique path scanned by 185.150.9.193 (🇨🇭) /vpn/js/../../vpns/cfg/smb.conf

    Poništi
  20. proslijedio/la je Tweet
    15. sij
    Prikaži ovu nit
    Poništi
  21. 15. sij

    I've Found two critical vulnerabilities in FACEIT AntiCheat engine. Happy to be part of hall of fame!

    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·