zodiacon Profile Banner
Pavel Yosifovich Profile
Pavel Yosifovich

@zodiacon

Followers
14K
Following
5K
Media
106
Statuses
3K

Windows Internals expert, author, and trainer. Teaching system programming & debugging at TrainSec. Check out my books & courses! 🚀 #WindowsInternals #TrainSec

New Jersey, USA
Joined October 2008
Don't wanna be here? Send us removal request.
@MalFuzzer
Uriel Kosayev
3 days
🚀 It’s official — my new book is live on Amazon: MAoS – Malware Analysis on Steroids This book is not like the others. It’s built on years of raw, hands-on research, reverse engineering sessions at 3 AM, and real-world incident response cases. Inside, you’ll find full A–Z
Tweet media one
42
196
1K
@StoryTrading
StoryTr🅰️ding⚡️📈
3 days
Missed the interview with $SNES CEO and CFO? The full interview is now available on @YouTube. Watch here 👇 https://t.co/hb6ghpNdy4
2
1
7
@AlanSguigna
Alan Sguigna
4 days
20 years ago, I read Andre Lamothe's "Tricks of the Windows Game Programming Gurus", the first book of its kind to teach low-level game programming and Windows design. Can AI modernize this code to run on modern Windows PCs? See my blog here: https://t.co/pPOuCumqkL
Tweet media one
0
4
12
@DebugPrivilege
DebugPrivilege
5 days
New blog post of me analyzing a crash dump with the bugcheck 0x9F. Root cause was a power IRP timeout in RAS SSTP during a device removal. The post walks PnP locks, the stuck IRP, and more, including my thought process. Check it out here: https://t.co/Vm2Da3TJXy
Tweet media one
3
57
172
@zodiacon
Pavel Yosifovich
8 days
Ever wondered how Process Explorer builds the process tree? I wrote a guide on how to code your own in C++. We cover PID reuse, parent vs. creator, recursion, and more. Read it here:
Tweet card summary image
trainsec.net
Learn how Windows builds process trees, why some processes appear parentless, how PIDs are reused, and how to code your own version in C++.
3
89
362
@invideoOfficial
Invideo
3 hours
Hailey Bieber’s Rhode could’ve dropped this million-dollar ad (they honestly should). Made on invideo for $100, that’s IT. Single prompt to million-dollar ad for your business. What are you creating today?
0
1
5
@KooKiz
Kevin Gosse
9 days
Out-of-process is not feature-complete yet, but it has a very significant impact on performance. When testing startup, I immediately notice if I accidentally switch back to in-process. I hope we can enable it by default soon.
@resharper
JetBrains ReSharper
10 days
Tried ReSharper 2025.2 out of process yet? Our lab saw a 61% reduction in long startup freezes (100 ms+). Read our blog post to find out how to set it up. We’d love to hear your results: https://t.co/QkhBdcM9aR
Tweet media one
4
4
29
@TrainSec
TrainSec Academy - Where pros train pros
11 days
@infoSecSki @zodiacon Yes, we offer Students & Freelancers discounts on all of our on demand products. The EDR Internals workshop specifically is already sold-out for the current dates. You should register to the waitlist and get updates if and when it's scheduled again.
0
1
7
@daem0nc0re
daem0nc0re
12 days
Added my implementation of file/directory hiding kernel driver. https://t.co/xVBUFYSLJw
Tweet media one
2
47
208
@TrainSec
TrainSec Academy - Where pros train pros
12 days
Update #1: Labor Day + September 1st = Double celebration TrainSec students get 35% off all Learning Paths until Sept 14. Code: LABORDAY25. Update #2: EDR Internals sold out → Join the waitlist for more dates: https://t.co/IVEgVbS27p Update #3: New article by @zodiacon:
Tweet card summary image
trainsec.net
This hands-on workshop is designed to give cybersecurity professionals, malware researchers, and detection engineers a rare opportunity to explore how modern Endpoint Detection and Response (EDR)...
2
6
32
@zodiacon
Pavel Yosifovich
17 days
I just released a new video: How WSL 1 Works. In this video, I explain how Windows Subsystem for Linux version 1 runs ELF binaries. https://t.co/s47zjYL9md
Tweet card summary image
trainsec.net
Windows Subsystem for Linux (WSL) first appeared in Windows 10 (Anniversary Update, 1607). It enables Linux binaries to run directly on Windows without recompilation. This capability is often...
5
51
192
@TrainSec
TrainSec Academy - Where pros train pros
19 days
Hardware Hacking Expert Level 2 led by @The_H1tchH1ker is coming soon, starting with the Advanced UART Hacking module. Students of Level 1 will receive a significant discount when Level 2 launches. https://t.co/UTYlZJbRG7
Tweet card summary image
trainsec.net
Transform yourself from a novice to a seasoned hardware hacking expert with our "Hardware Hacking Expert" course. This comprehensive path, combining dynamic
1
3
17
@TrainSec
TrainSec Academy - Where pros train pros
23 days
Kernel allocation tags in Windows—why they exist and how to use them for debugging and forensics. New video + blog post from Pavel Yosifovich, free in the TrainSec Knowledge Library. Watch & read:
0
6
15
@TrainSec
TrainSec Academy - Where pros train pros
1 month
Ever wondered what really happens when you delete a file in Windows? In the new video, Pavel Yosifovich traces every step. Watch the deep dive:
Tweet card summary image
trainsec.net
Starting with Windows Vista, Microsoft introduced protected processes—special executables the kernel shields from injection, memory reads/writes and handle duplication. Windows 8.1 broadened the idea...
1
8
33
@update_conf
Update Conference
1 month
The sun’s still shining and so is our Summer Sale! ☀️ Level up with Update Courses - online programs for .NET developers by .NET developers: @konradkokosa • @Scooletz • @lukaszpyrzyk • @danielmarbach • Stephen Cleary • @marcgravell • Sebastian Solnica • @KooKiz •
Tweet media one
0
2
5
@leanpub
Leanpub
1 month
Windows 10 System Programming, Part 1 by Pavel Yosifovich is on sale on Leanpub! Its suggested price is $37.95; get it for $21.56 with this coupon: https://t.co/IKyUgV8Mjm @ZODIACON
Tweet card summary image
leanpub.com
null
0
4
18
@DebugPrivilege
DebugPrivilege
1 month
Hi all - I'm hiring a Principal Security Researcher who has strong knowledge in Active Directory and Entra ID. Are you interested in spending time to find the next ZeroLogon or BadSuccessor equivalent, as well as helping our product to improve? Go apply:
linkedin.com
Posted 11:05:03 AM. About UsAt Netwrix, our mission is to revolutionize data security by placing identity at the core -…See this and similar jobs on LinkedIn.
3
30
95
@ocornut
Omar 🍋
1 month
dear imgui 1.92.2 release https://t.co/PErbkOHthD - improving tab bar resizing logic (combining shrinking and scrolling). - misc keyboard nav fixes, table fixes, font fixes & many others. - backend fixes (vulkan+linux w/ some drivers, SDL_GPU use SDL_GPUTexture* as texture id).
Tweet media one
Tweet media two
Tweet media three
Tweet media four
3
46
348
@the_fanstop
College Shirt Clubs by The Fan Stop
1 year
Indiana Hoosiers Shirt of the Month Get officially-licensed Indiana Hoosiers T-shirts, long-sleeve & hoodies monthly
0
6
123
@MalFuzzer
Uriel Kosayev
1 month
Just published my new article in the TrainSec Knowledge Library: "Two Sides of the Same Coin – From Dissected Malware to EDR Evasion" Understanding how malware works is key to learning how to bypass and defend against EDR. A must-read for TrainSec students. Read here:
0
13
38
@inside_IL_intel
Inside_Israel_Intel
1 month
15
188
589
@TrainSec
TrainSec Academy - Where pros train pros
1 month
New video by @zodiacon: set up real kernel debugging for a Windows VM in minutes. From bcdedit to live breakpoints in WinDbg—watch the walkthrough and start debugging the kernel. Full guide + courses at TrainSec https://t.co/d8PzSvXGw9
Tweet card summary image
trainsec.net
In just 25 minutes the walk-through shows you how Windows Management Instrumentation (WMI) reveals almost every measurable or configurable detail in Windows.
0
5
22