Ulf Frisk
@UlfFrisk
Followers
8K
Following
9K
Media
220
Statuses
2K
IT-Security Minion | https://t.co/N1gIUL5rKc | https://t.co/XbBOnQPYoK | DMA | PCILeech | MemProcFS
Sweden
Joined April 2016
The PCILeech and MemProcFS projects have a Discord server! Join today at https://t.co/7NN8bgUFZQ !
5
13
54
Offensive SIEM 👊🏽 Flip your SIEM mindset from reactive detection to proactive hunting. Uncover local privilege escalations, hidden misconfigs, and even potential #CVE before attackers do 🔥🔥 🎥 https://t.co/plLZbEByOf
#BlueTeam #SIEM #CyberSecurity #ThreatHunting #DFIR
4
11
70
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
dirkjanm.io
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise...
141
905
3K
The @SEC_T_org organizers posted the video from my talk "Crowdsourcing Bluetooth identity, to understand Bluetooth vulnerability" in what seems like record time. You can find the video & slides (and previous truncated-for-time version) here:
darkmentor.com
Bluetooth vulnerability assessment is still in the dark ages. We still don't have a good handle on all the devices that are affected by the exploitable-over-the-air vulnerabilities that we disclosed...
0
6
11
All recorded talks (except lightning talks) are now up on YouTube! https://t.co/wX2H4HRjOf
https://t.co/wX2H4HRjOf
youtube.com
0
6
16
Market turbulence calls for balance. Gold could help your portfolio hold steady.
4
9
172
hashcat v7.0.0 released! After nearly 3 years of development and over 900,000 lines of code changed, this is easily the largest release we have ever had. Detailed writeup is available here: https://t.co/fxAIXNXsEr
22
375
1K
Some new techniques of code injection in Hyper-V guest VM in compare with Pcileech by @UlfFrisk and Hyper-V Virtual machine plugin for MemProcFS? It will be interesting, I suppose. https://t.co/IR0CVL6vdo
We’re proud to have Andrei Lutas, Senior Team Lead at Bitdefender, presenting live at REcon 2025 in Montreal. 🎤 Andrei will introduce HyperVinject—a powerful new tool that enables code injection into a running Hyper-V VM (Child Partition) directly from the Root Partition, along
0
2
16
NetworkMiner 3.0 Released! 🔐 QUIC 🏭 CIP (EtherNet/IP) 🏭 UMAS (over Mobdus) 👾 Remcos RAT 🔍 Improved OS fingerprinting 🐧 Better Linux integration https://t.co/tIyWMzls5L
netresec.com
I am very proud to announce the release of NetworkMiner 3.0 today! This version brings several new protocols as well as user interface improvements to NetworkMiner. We have also made significant...
0
36
78
I’ve posted a detailed explanation of why the claimed ESP32 Bluetooth chip “backdoor” is not a backdoor. It’s just a poor security practice which is found in other Bluetooth chips by vendors like Broadcom, Cypress, and Texas Instruments too. https://t.co/Z2cgi8v0ne
darkmentor.com
This post refutes the claim that researchers found a "backdoor" in ESP32 Bluetooth chips. What the researchers highlight (vendor-specific HCI commands to read & write Controller memory) is a common...
🔷 A backdoor in the ESP32 chip would allow it to infect millions of devices. Miguel Tarascó and @antonvblanco have revealed this at the @rootedcon this backdoor and presented a tool to perform Bluetooth security audits on any gadget. https://t.co/Q646g8s1vS
2
114
249
https://t.co/JE68XbHamM Our newest research project is finally public! We can load malicious microcode on Zen1-Zen4 CPUs!
github.com
### Summary Google Security Team has identified a security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside...
13
283
813
Character and style consistency just became effortless. Nano Banana Pro is now in FLORA.
0
3
33
I captured the entire "Planetary Parade" using my 11" telescope, and combined everything into one composite photo that stayed true to the angular scale of these objects. Made entirely with real photos, I hope this composite helps illustrate the scale of these things!
2K
12K
87K
🎉 In just one week (January 30 & 31), we will hold our first “Defeating Microsoft’s Default BitLocker Implementation” training session of 2025 in Zurich! Dive into the training program featured at Black Hat USA 2023 & 2024 and explore hardware hacking while learning how to break
1
5
25
I'm from Berlin. Afghanistan gets better tech than Europeans now. It's not a joke. It's the result of 30 years of suffocating regulation. And now, the EU's new AI Act is about to make it 10x worse. Here's the tragic story of how the EU is killing our tech future 🧵:
454
2K
11K
Updated PCILeech/MemProcFS to support Intel macs as well. Previously only Apple silicon macs were supported.
PCILeech PCIe DMA attacks and MemProcFS memory forensics now runs on macOS analyzing Windows memory! MemProcFS 5.14 and PCILeech 4.19 just released! https://t.co/inOM3l2eyd
https://t.co/KuTVVzZJUR
1
13
56
FLY Investors: We’re evaluating potential claims for investors who owned Firefly Aerospace Inc. stock between 8/07/2025 and 9/29/2025. See if you’re eligible to seek recovery your losses. (Attorney Advertising. No cost or obligation.)
0
4
11
PCILeech PCIe DMA attacks and MemProcFS memory forensics now runs on macOS analyzing Windows memory! MemProcFS 5.14 and PCILeech 4.19 just released! https://t.co/inOM3l2eyd
https://t.co/KuTVVzZJUR
6
71
212
Updated version of Hyper-V Virtual Machine plugin for MemProcFS by @UlfFrisk: https://t.co/XzDAtOANC7
0
1
14
We’ve now scheduled our next Network Forensics for Incident Response training 📅 Dates: May 12-15, 2025 🕑 Duration: Four half-days 🌐 Type: Live Online Network Forensics Training 💵 Price: € 960 EUR https://t.co/gvkCJodIRx
netresec.com
Upcoming Network Forensics Trainings and Classes from Netresec
1
4
18
Part 5 of @j00ru's Windows Registry Adventure is out! https://t.co/gMRLzReeC9 Incredible depth of knowledge on display, and good to see it shared as a reference with the world ❤️
0
45
119
Have you integrated APOL1 genetic testing into your practice? Discover the No-Cost APOL1 Genotyping Program for eligible patients sponsored by Vertex Pharmaceuticals—helping you deliver precision care without added cost. Learn more today!
21
23
227
If you like Windows internals + x86_64 follow: @sixtyvividtails @ivanrouzanov @C5pider @mrexodia @yarden_shafir @chompie1337 @timmisiak @Intel80x86 @_winterknife_ @horsicq @d_olex @UlfFrisk @aall86 @zodiacon @standa_t @0vercl0k @PetrBenes @zwclose @rwfpl @TheEnergyStory
12
35
163
This is what you need to listen to @DairyatGuelph your narrative is not science it's opinion, driven by the the lust for cobtrol of Bill Gates who is buying up farmland ...who stands to gain?
46
497
1K
🆕 Check out our latest publication on DMA attacks via SD cards! 💾 The article was written by our researcher Gesser. ➡️ https://t.co/I4ujGaggJ2
3
39
76