sessionpool's profile picture. security, kernel, debugging, hacking, research..

sessionpool

@sessionpool

security, kernel, debugging, hacking, research..

Breaking VSM by Attacking SecureKernel youtu.be/pm1ejZ3LkYU via @YouTube


sessionpool reposted

The slides and videos from my @USENIXSecurity WOOT 2020 talk are now posted: usenix.org/conference/woo…


sessionpool reposted

Capturing Network Packets from Windows endpoints leveraging built-in ETW mechanisms via Netsh ⚔️and Azure cloud native services via Azure Network Watcher extensions 🌩️ Documenting and extending the concepts behind @Mordor_Project PCAP files 😈 medium.com/threat-hunters…


sessionpool reposted

Happy to share that @JosephBialek and I just published a new research paper that analyzes the effort of enabling SMAP for NTOS: github.com/microsoft/MSRC… We'd love to discuss && hear other perspectives :)


sessionpool reposted

Finallly! My write-up on KDP is online! 🍾🍾

Kernel Data Protection is a new technology that prevents data corruption attacks by protecting parts of the Windows kernel and drivers through a set of APIs that provide the ability to mark some kernel memory as read-only: msft.it/6012TmrK2



sessionpool reposted

It has been a long journey! After almost a year of work the first draft of my book about performance analysis and tuning is ready.🎉 I know many people are struggling these days so I decided to make the book FREE. I'm looking for people who would like to review the book. (1/2)

dendibakh's tweet image. It has been a long journey!

After almost a year of work the first draft of my book about performance analysis and tuning is ready.🎉

I know many people are struggling these days so I decided to make the book FREE.

I'm looking for people who would like to review the book.
(1/2)

sessionpool reposted

A recording of today's presentation of "10 Years of Linux Security - A Report Card" is now available to view here: youtu.be/F_Kza6fdkSU PDF: grsecurity.net/10_years_of_li… PPT: grsecurity.net/10_years_of_li…

opensrcsec's tweet image. A recording of today's presentation of "10 Years of Linux Security - A Report Card" is now available to view here: youtu.be/F_Kza6fdkSU PDF: grsecurity.net/10_years_of_li… PPT: grsecurity.net/10_years_of_li…

sessionpool reposted

Video of my keynote in @OPCDE #6 is up and it has the coolest cover photo ever! Had so much fun in my first virtual conference. Thank you @msuiche for organizing it and inviting me and thanks to anyone who watched!

Kernel Data Protection is a new technology that prevents data corruption attacks by protecting parts of the Windows kernel and drivers through a set of APIs that provide the ability to mark some kernel memory as read-only: msft.it/6012TmrK2



vOPCDE #6 - WinDbg: time to put the @ back in the bag (Yarden Shafir) youtu.be/eONddXQjy2k


sessionpool reposted

If you are curious about how DMA remapping (VT-d) can be configured to protect memory from DMA, here is a short introduction to it with sample code. standa-note.blogspot.com/2020/05/introd… Code: github.com/tandasat/Hello…

standa_t's tweet image. If you are curious about how DMA remapping (VT-d) can be configured to protect memory from DMA, here is a short introduction to it with sample code.
standa-note.blogspot.com/2020/05/introd…

Code: github.com/tandasat/Hello…

sessionpool reposted

#Sysmon 11 is out with a new Event type and several improvements! I’ve published a blog post detailing all new features here: medium.com/falconforce/sy… #DFIR #Sysinternals #ThreatHunting


sessionpool reposted

Bored in isolation? Do not despair! #OffensiveCon20 videos are now up! youtube.com/playlist?list=…


sessionpool reposted

Let's write a new bootloader for x86 in Rust twitch.tv/gamozo


sessionpool reposted

Guys & girls! Exactly a year ago I promised over 15 bugs in win32k. You're welcome to read and find out about my biggest research so far: #win32k #SmashTheRef bug class - github.com/gdabah/win32k-… Check out the paper and the POCs, there are some crazy stuff going on. Promise!


sessionpool reposted

First part of a research on Windows Defender main driver - WdFilter n4r1b.netlify.com/en/posts/2020/…


sessionpool reposted

Recon 2019 video have been released recon.cx/2020/montreal/


sessionpool reposted

we have an update to DTrace on Windows. with the latest 20H1 insider build, no more KD required to use dtrace on windows. plus arm64 MSI. techcommunity.microsoft.com/t5/windows-ker…


sessionpool reposted

The 7th part of the tutorial Hypervisor From Scratch is published! In this part, I described EPT. Thanks to Petr @PetrBenes as Hypervisor From Scratch could never have existed without his help and to Alex @aionescu for patiently answering my questions. rayanfam.com/topics/hypervi…


Loading...

Something went wrong.


Something went wrong.