OnlyTheDuck Profile Banner
cbayet Profile
cbayet

@OnlyTheDuck

Followers
2K
Following
1K
Media
9
Statuses
399

Security expert and CTO @Reverse_Tactics

Joined April 2017
Don't wanna be here? Send us removal request.
@OnlyTheDuck
cbayet
1 month
Love the top-bottom approach of this blogpost ! A great way to explain internals in my opinion, and the kind of reference you look when you're trying to exploit a heap bug. Also glad to see that our paper (with @paulfariello) of 2020 is still relevant !.
@r0keb
ö
1 month
Good morning! Just published a blog post diving into Windows Kernel Pool internals: basics, memory allocation functions, internal structures, and how Segment Heap, LFH, and VS work.
0
2
14
@OnlyTheDuck
cbayet
2 months
Jet lag hit hard but still really enjoyed @typhooncon, Seoul and meeting new friends 😁.
@Reverse_Tactics
REverse_Tactics
2 months
@typhooncon is already over, but we enjoyed every minute ! During our talk "Journey To Freedom", we disclosed for the first time the details on the Windows LPE we used at Pwn2Own Vancouver 2024 after escaping from VirtualBox. Slides are already available:
0
0
11
@OnlyTheDuck
cbayet
3 months
RT @typhooncon: 🌪️ Back from lunch just in time to escape VirtualBox and unchaining objects in the Windows Kernel with Corentin Bayet https….
0
6
0
@OnlyTheDuck
cbayet
3 months
RT @Reverse_Tactics: Slides and video of our talk at @offensive_con are already online !.Thanks to @Binary_Gecko for the amazing event.http….
0
12
0
@OnlyTheDuck
cbayet
3 months
@offensive_con Let me know if you'll be at @typhooncon !.
0
0
4
@OnlyTheDuck
cbayet
3 months
Had a blast at @offensive_con and #Pwn2Own ! Going to sleep now, but not for long. .
@Reverse_Tactics
REverse_Tactics
3 months
And that's a wrap for @offensive_con and #Pwn2Own ! We had the best time there and were so glad to reunite with the finest researchers out there. See you next year !.
2
1
20
@OnlyTheDuck
cbayet
3 months
RT @thezdi: Sweet! Corentin BAYET (@OnlyTheDuck) from @Reverse_Tactics barely needed a second to demonstrate his exploit against VMware ESX….
0
10
0
@OnlyTheDuck
cbayet
3 months
RT @Reverse_Tactics: It's time for @offensive_con and #Pwn2Own ! Come meet us there and and attend our sessions:. 📅 Fri, May 16 @ 18:45 — O….
0
2
0
@OnlyTheDuck
cbayet
4 months
So proud to speak for the first time @offensive_con ! Excited to be there and meet the finest researchers 🍻.
@Reverse_Tactics
REverse_Tactics
4 months
Our talk "Journey to Freedom" about our Pwn2Own 2024 VirtualBox escape is coming to @offensive_con ! We will dive deeper into the technical challenges and obstacles we faced. @OnlyTheDuck will break down the key research phases and the exploit's most critical components.
0
1
16
@OnlyTheDuck
cbayet
4 months
Still a few seats available for our next session at @reconmtl !.
@Reverse_Tactics
REverse_Tactics
4 months
📢 We're excited to announce our complete training catalog is now live at !.Next up: "Bug Hunting In Hypervisors" at @reconmtl Register here:
0
2
2
@OnlyTheDuck
cbayet
5 months
RT @typhooncon: 🌪️ Speaker Announcement!. Excited to welcome @OnlyTheDuck to the #TyphoonCon2025 Conference lineup!.Join us in Seoul on May….
0
4
0
@OnlyTheDuck
cbayet
6 months
RT @SinSinology: it took me so much time to finish this exploit but I finally did it! my first guest-to-host virtualbox escape is finally r….
0
135
0
@OnlyTheDuck
cbayet
6 months
If you see hypervisors as magic black boxes that are hard to break, join us to this training and learn to apply your reverse, bug hunting and exploit knowledge to build VM escapes !.
@Reverse_Tactics
REverse_Tactics
6 months
For the first time, our training "Bug Hunting in Hypervisors" is open to the public at @reconmtl !.Designed for security researchers,we will dive into VM escapes, hypervisor attack surfaces, and real-world exploitation. More info:
0
12
31
@OnlyTheDuck
cbayet
7 months
GG @SinSinology !!.
@thezdi
Trend Zero Day Initiative
7 months
And that��s a wrap! #Pwn2Own Automotive 2025 is complete. In total, we awarded $886,250 for 49 0-days over the three day competition. With 30.5 points and $222,250 awarded, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) is our Master of Pwn. #P2OAuto
Tweet media one
0
0
5
@OnlyTheDuck
cbayet
7 months
RT @thezdi: And that’s a wrap! #Pwn2Own Automotive 2025 is complete. In total, we awarded $886,250 for 49 0-days over the three day compet….
0
40
0
@OnlyTheDuck
cbayet
9 months
RT @Reverse_Tactics: Slides & video from our @GrehackConf talk "Attacking Hypervisors - A Practical Case" are online! Learn how we exploite….
0
28
0
@OnlyTheDuck
cbayet
9 months
RT @Reverse_Tactics: Join us live at @GrehackConf for @OnlyTheDuck's talk "Attacking Hypervisors : A practical case" at 4PM (paris time)! h….
0
4
0
@OnlyTheDuck
cbayet
9 months
RT @Reverse_Tactics: Ready for @GrehackConf ! This Friday, catch @OnlyTheDuck's talk "Attacking Hypervisors: A practical case". If you're a….
0
4
0
@OnlyTheDuck
cbayet
10 months
RT @natashenka: Exciting update on Project Zero’s LLM research:
0
38
0