Reverse Engineer @ Microsoft (MIRAGE)

Joined January 2020
16 Photos and videos
⚠️ RIFT Update ⚠️ We’ve just shipped a new update to RIFT: • Customize values and add missing libraries if crate extraction falls short • Configure RIFT more easily • Support for the latest Rust compilers • Improved installer script github.com/microsoft/RIFT #infosec #msft
1
84
Andreas Klopsch retweeted
The Russian military intelligence actor Forest Blizzard has conducted large-scale exploitation of vulnerable small office/home office (SOHO) devices to hijack DNS requests and enable persistent, passive visibility and reconnaissance at scale. msft.it/6012Q24hI By compromising edge devices that are upstream of larger targets, threat actors could take advantage of less closely monitored assets to pivot into enterprise environments. We have identified over 200 organizations and 5,000 consumer devices impacted by Forest Blizzard’s malicious DNS infrastructure. Microsoft Threat Intelligence is publishing this research to increase awareness of the risks associated with insecure home and small-office internet devices and to give users and organizations tools to mitigate, detect, and hunt for these threats where they might be impacted.
9
92
224
29,566
⭐ RIFT Major Rearchitecture! Now more modular, extensible, and easier to use New experimental build 3 modes: file analysis, direct generation, HTTP API service Improved IDA Plugin! github.com/microsoft/RIFT #reverseengineering #malware #cybersecurity #infosec #RIFT
8
23
1,814
🚨 RIFT Update 🚨 Improved rustc compiler detection ✅ Fixed bugs causing incorrect FLIRT signatures for nightly builds 🛠️ Plus, multiple stability fixes! We’re making RIFT easier to use—big features coming soon 😎 👉 github.com/microsoft/RIFT #RIFT #rust #microsoft #infosec
3
118
Andreas Klopsch retweeted
Lots of frustration in the malware analysis and reverse engineering community. It's been discovered a DEFCON talk, presentation, and the code which coincided with it, was AI slop. The talk itself had hallucinated terminology which (apparently) no one at DEFCON noticed. Bad.
72
166
3,248
154,979
RT @MalwareRE: #PipeMagic is a highly modular backdoor used by the financially motivated threat actor Storm-2460. It masquerades as a legit…
16