Saleh
@S4l3hh
Followers
389
Following
3K
Media
1
Statuses
126
1ooi3oS8, PhD in Hardware Sec @VernamGroup, sometimes working on @Hyperdbg!
Massachusetts, USA
Joined April 2012
Our paper "TRM: The Reversing Machine" has been accepted to @asiaccs2026! TRM is developed on top of @HyperDbg and exposes stealthy sub-OS malware using transparent hypervisor introspection, detecting threats missed by 24 AV engines. Preprint https://t.co/TYomqGJiV1
@Intel80x86
arxiv.org
Existing anti-malware software and reverse engineering toolkits struggle with stealthy sub-OS rootkits due to limitations of run-time kernel-level monitoring. A malicious kernel-level driver can...
0
3
20
Chypnosis: Undervolting-based Static Side-channel Attacks to appear in @IEEESSP Precisely dropping chip voltage disables clocks/sensors but retains data, enabling static SCA extraction With Kyle Mitard, @S4l3hh, Fatemeh Dana, @yuvalyarom & Shahin Tajik https://t.co/OUCfnvQ4B9
1
6
8
HyperDbg v0.15 is out! β¨π This version comes with a new SMM interrupt (SMI) command, fixing issues with Intel CET emulation for SYSCALL/SYSRET on 11th Gen+ (Tiger/Rocket Lake) CPUs, also saving/restoring XMM registers on VM-exits/entries. Check it out: https://t.co/dlH2K8hbas
3
23
76
More info on HyperEvade: https://t.co/6HfB6jD9LR Microsleep function: https://t.co/2R3xGtfvb7 and RDTSC/RDTSCP: https://t.co/7nK64ZrBMO
https://t.co/KzZwRHNnGE (2/3)
1
5
26
I'm happy to announce that @HyperDbg v0.14 is released! This version includes HyperEvade (beta preview), fixes Win11 24H2 compatibility issues, and adds multiple timing functions to the script engine (Special thanks to @0Xiphorus). Check it out: https://t.co/27biDbzvDs (1/3)
1
24
69
HyperDbg v0.13.2 is out! π This version brings improvements and fixes stability issues in nested virtualization on Intel Meteor Lake processors. Check it out: https://t.co/fI1jD88xSV
github.com
HyperDbg v0.13.2 is released! If youβre enjoying HyperDbg, donβt forget to give a star π on GitHub! Please visit Build & Install to configure the environment for running HyperDbg. Check out the...
1
11
60
HyperDbg v0.13.1 has been released. π« This version includes improved mitigations against anti-hypervisor techniques used to detect nested virtualization environments, along with various bug fixes. Check it out: https://t.co/3rsIefo0qv
github.com
State-of-the-art native debugging tools. Contribute to HyperDbg/HyperDbg development by creating an account on GitHub.
2
33
116
Not Windows sec, but if you're into hardware design & FPGA synthesis, check out our new paper about our RTL-level hardware (chip and IP core) debugger, hwdbg. Thanks to @S4l3hh and Soroush. Note that hwdbg is still a work in progress, but worth a read. π https://t.co/yZ2qlGzrkB
dl.acm.org
0
15
69
If you're looking for better tools and a high Return on Investment (ROI), both @HyperDbg and @x64dbg are free, as in open-source and free beer.
Debugging costs money. You can spend cash on better tools and training for your team, or you can spend engineering time as the bugs elude you and your schedule slips. What has the better Return on Investment? Here's a sample ROI model: https://t.co/qE5QFfNUuS
2
8
58
The first HyperDbg release of 2025 is out! π This version (v0.12) introduces commands for PCI/PCI-e device tree enumeration and IDT dumping, plus many bug fixes. Huge thanks to @0Xiphorus, @reodus_, @binophism & other contributors! π Check it out: https://t.co/OVuLIekfAY
4
37
95
Happy New Year, everyone! ππ Wishing you all a fantastic year ahead. This year, weβre aiming to introduce exciting new features in HyperDbg, mostly around PCI Express, UEFI, and firmware debugging. As always, your contributions are greatly appreciated! π«
0
1
27
HyperDbg v0.11 is released! β¨ This version comes with bug fixes, improvements, and two new commands for viewing Local APIC (XAPIC/X2APIC) and IO APIC. Big shoutout to @0Xiphorus for joining the team for bringing PCIe support to HyperDbg! https://t.co/lyMhKiq4g8
1
14
48
HyperDbg v0.10.2 is released! This release comes with lots of bugfixes and improved stability, check it out here:
github.com
HyperDbg v0.10.2 is released! If youβre enjoying HyperDbg, donβt forget to give a star π on GitHub! Please visit Build & Install to configure the environment for running HyperDbg. Check out the...
0
9
46
With the #GhostWrite CPU vulnerability, all isolation boundaries are broken - sandbox/container/VM can't prevent GhostWrite from writing and reading arbitrary physical memory on affected RISC-V CPUs. Deterministic, fast, and reliable - no side channels. https://t.co/qtmosPvuYl
8
160
504
Community links πβ¨ Telegram Group: https://t.co/U0ZDLLv8e4 Discord Server: https://t.co/aHpW2HBSRD Matrix Group: https://t.co/342KdmCLbv Mastodon: https://t.co/JAKjftUQhH
0
3
13
Are you into hypervisor security and fuzzing? Consider applying for a PhD position in my group. More info:
0
29
78
Starting from v0.10 (next version), HyperDbg uses @keystone_engine as its assembler. β€οΈ Thanks to our new team member @AbbasMasoumiG for adding it. The following commands are added to assemble virtual and physical memory: - https://t.co/LcmRKKTsr9 -
0
9
31
Take advantage of VMware Workstation being free! β¨ Perfect time to learn hypervisor-based reverse engineering. Check out the HyperDbg tutorial at: https://t.co/P7T6IWZutb
https://t.co/jQN6zn9sIV
youtube.com
View the full free MOOC at https://ost2.fyi/Dbg3301. This course is an introductory guide to HyperDbg debugger, guiding you through the initial steps of usin...
π₯ Summer's heating up, and so is the learning! VMware Workstation is now free, making it the perfect time to dive into hypervisor-based reverse engineering. Check out the free HyperDbg tutorial at @OpenSecTraining: https://t.co/I1n3ggYlU9 (preferred) https://t.co/119iZNhSsA
0
12
75
π₯ Summer's heating up, and so is the learning! VMware Workstation is now free, making it the perfect time to dive into hypervisor-based reverse engineering. Check out the free HyperDbg tutorial at @OpenSecTraining: https://t.co/I1n3ggYlU9 (preferred) https://t.co/119iZNhSsA
youtube.com
View the full free MOOC at https://ost2.fyi/Dbg3301. This course is an introductory guide to HyperDbg debugger, guiding you through the initial steps of usin...
0
21
92