Aidan Khoury
@aidankhoury
Followers
2K
Following
1K
Media
4
Statuses
185
Yet another very powerful patchguard and vbs compliant method for hooking system calls globally https://t.co/F8ImYDU1ki
revers.engineering
Abuse the HalPrivateDispatchTable to hook SYSCALL system-wide while maintain compliance with PatchGuard on Windows 10 and 11.
5
65
179
Awesome to see @riotgames using HVCI to protect the kernel against bad drivers and DMA attacks ๐ช
VAN: RESTRICTION HVCI Vanguard added a new restriction. Players now may need to enable HVCI to be allowed to launch VALORANT. Enabling HVCI (Hypervisor-Protected Code Integrity) ensures system integrity by disallowing unsigned code to be executed in the kernel. This prevents
8
13
93
vanguard 2 now on league of legends, cheating to be deprecated this patch https://t.co/kd3szRHDHT
32
17
103
Helldivers 2 got review-bombed by players complaining about their anti-cheat, so I reached out to anti-cheat leaders from Riot Games, Roblox, and Fortnite to get their take. Are players over-reacting to kernel-level anti-cheat drivers? Full story:
pushtotalk.gg
push to talk #8 // feat. people who've led anti-cheat for Riot Games, Roblox, and Fortnite
56
137
786
I do not believe we are successful just because it operates at the kernel level. Any company can develop a kernel driver. EAC, Battleye, and Ricochet all have kernel drivers. The reason Vanguard has been successful is that our engineers are pushing the envelope in this space by
valorants kernal anti cheat has been one of the biggest success stories in gaming when it comes to combating cheaters, yet this goes under the radar, why is that?
59
96
2K
the jury in Epic v. Google has just delivered its verdict. It found that Google turned its Google Play App Store and Google Play Billing service into an illegal monopoly
theverge.com
Victory Royale.
219
1K
9K
Truly the best in the industry.
A big shoutout goes to @nickeverdox for creating something to combat DMA cheats. This is an incredibly difficult and challenging task, and an industry first. Without this, there would be no way to prevent or detect these DMA cheats in general thanks to him he has pushed the space
1
1
11
AC engineers always pushing the envelope this is pretty impressive!
Yet another very powerful patchguard and vbs compliant method for hooking system calls globally https://t.co/F8ImYDU1ki
3
1
21
Valorantโs anti cheat was made by god. 1 hacker in 2,000 games and he got banned before round 5. Meanwhile CS2 they forced play their ghetto third world country Faceit servers ๐๐๐
66
74
3K
@CoreNoort @securityfreax People in re/infosec circles rediscover concepts cheat developers (kids) have relied upon for years fairly often. You can find cases of this happening by googling usage of win api calls on cheat dev forums and compare against re/infosec blogs.
1
2
15
Intel has just announced that its top Arc A770 GPU is going on sale on October 12th for $329. That's the same price as an RTX 3060, and Intel's A770 is expected to comfortably outperform the RTX 3060. Full details here: https://t.co/u94OfgfSfh
30
97
1K
Improving MBA Deobfuscation using Equality Saturation by @fvrmatteo and @mr_phrazer. https://t.co/JPYwVfrLQW
secret.club
This blog post will first give a brief overview of obfuscation based on Mixed-Boolean-Arithmetic (MBA), how it has historically been attacked and what are the known limitations. The main focus will...
0
73
140
Since I have joined the @RiotVanguard team I have documented and tracked over 200 Threats, and created over 2300+ Detections. and banned a ton of cheaters. I can proudly announce today I have now been promoted to Senior Anti-cheat Analyst, I am only more hungry to push further.
344
129
7K
[1/n] Before I left Kaspersky, I had one more UEFI related research along with @vaber_b in the pipeline that wasn't released thus far. This research on a little known UEFI firmware implant has now become public with the amazing help of @JusticeRage. A ๐งต
New blog post about an UEFI firmware bootkit! https://t.co/zDXWFOjf7z Research was led by our dearly missed @_marklech_
1
49
124
To editorialize a bit - this is bad. You should own your own machine.
0
1
3
This is just a leap towards static ROT. It's annoying for them to have to find a way to "trust" the various signed shims floating around let alone the moklist contents they may measure in and so they just kick it to the curb all together. This is obviously less important on
Some more detailed thoughts on somenew systems shipping without allowing Linux to be booted by default, and how if Microsoft wants to be in charge of deciding what systems can boot, they need to actually talk to the rest of the community:
3
2
12
I've heard this argument bunch of times. And it sounds plausible, until I realize the last time I did "ctrl+f static_cast" was... never.
@Love2Code @MittringMartin It is c++ way of doing casting, I've heard, don't remember where, that is suppose to help you find casting code (by ctrl+f in most ide/code editors)
1
1
9
There's a huge difference between knowing the name of something and knowing something. We talk in fact-deficient, obfuscating generalities to cover up our lack of understanding.
55
1K
6K
I seldom touch my xbox but sat down this afternoon to play some Dying Light. It's peculiar to me that I cannot play any single player game that I own while there is a service outage, nor in "offline mode", nor while xbox is set as "home xbox".
2
5
38