Nous sommes à la recherche de volontaires pour réaliser le challenge SSTIC 2025 !
Si vous êtes intéressé vous pouvez retrouver les informations pour nous contacter sur sstic.org/ !
Bonne fêtes ☃️
github.com/commial/experimen… Little experiment about reusing Windows Defender built-in unpackers, mostly for fun (based on the very useful @taviso's loadlibrary)
Even if it works for some (old) commercial packers, it seems that nowadays malware authors prefer one-time & custom packers... So likely not that useful, but still fun to make 🤷
Do you wish Time Travel Debugging was faster and more lightweight? Our latest version lets you decide exactly what you want recorded! Select modules to record or use the API for full control. Get your recording just the way you like it. Crusts optional. aka.ms/ttd
First big result from our new CPU research project, a use-after-free in AMD Zen2 processors! 🔥 AMD have just released updated microcode for affected systems, please update! lock.cmpxchg8b.com/zenbleed.…
A short🧵 detailing a Kerberos LPE I discovered while working with @tiraniddo on our BlackHat research.
msrc.microsoft.com/update-gu… (CVE-2023-21817)
This was fixed in Feb, but I think some will find the vulnerability & exploitation interesting.
1/
The results are out!
We are very honoured to have won first place🥇in the Hex-Rays plugin contest 2022 🎉
Our entry was "ttddbg", a time-travel debugging plugin for IDA already presented at #SSTIC 2022.
Many congratulations to all the other entrants!
🥁 We have the winners of the Hex-Rays Plugin Contest 2022! Our congratulations go to:
🥇 ttddbg by @simsor and @citronneur
🥈 ida_kcpp by Uriel Malin and Ievgen Solodovnykov
🥉 FindFunc by Felix B.
Take a look at the full list: hex-rays.com/contests_detail…#PluginContest#IDA
New release of github.com/commial/ttd-bindi…, featuring more API wrapping (thanks @citronneur), and new examples: coverage (LightHouse compatible) and a trace producer for the awesome Tenet plugin (cc @gaasedelen)
ALT Loading a TTD trace into IDA Tenet
ALT Viewing a TTD trace coverage with IDA LightHouse
After 3 years of development, today we proudly announce & celebrate the first release of a new hypervisor-based user-mode & kernel-mode debugger, @HyperDbg. 🎉
As an alternative to #Windbg, HyperDbg is mainly built for analyzing, reversing, and fuzzing!
github.com/HyperDbg/HyperDbg