
π π π π π π
@felixm_pw
Followers
1K
Following
4K
Media
59
Statuses
1K
Senior Researcher @Sophos | https://t.co/rAj5k8LMif
π¬π§ United Kingdom
Joined May 2018
With some guidance from @DebugPrivilege I've found a way to easily dump clear text implants even while they sleep. Bad day for sleep obfuscation π€.
15
102
316
RT @DebugPrivilege: Ever tried VSS tracing? Iβve been using it to troubleshoot Volume Shadow Copy issues. Itβs super useful but not widelyβ¦.
0
12
0
RT @Octoberfest73: Really cool work in this blog. My answer to the Time Travel Debugging problem attached. Using timers (Ekko) for sleep, aβ¦.
0
15
0
This evening @DebugPrivilege walked me through some case studies from the WinDBG section of his debugging fundamentals repo. Defiantly check it out and bookmark it! .
7
19
57
RT @eversinc33: I just finished writing the final part of my anti-anti-rootkit series, where I do a slight twist on the .data ptr hijackingβ¦.
0
73
0
RT @eversinc33: It doesnt have to be RISC-V :) Wrote a little MIPS I VM (based on a playstation emulator I started writing years ago) thatβ¦.
0
11
0
RT @S0ufi4n3: The (Anti-)EDR Compendium.EDR functionality and bypasses in 2024, with focus on undetected shellcode loader. .
0
69
0
RT @eversinc33: Yesterday I finally finished part II of my anti rootkit evasion series, where I showcase some detections for driver "stompiβ¦.
0
112
0
Really cool write-up about North Korean actors abusing malicious NPM packages by my friend @0xpoppaea .
1
0
1
RT @x33fcon: #Maldev - Packer Development is going strong in a #workshop at #x33fcon being taught by @ShitSecure and @eversinc33 - #redteamβ¦.
0
3
0
Just got linked this really awesome blog by @_vanvleet about Detection Data Models. This should be a valuable read for my Detection Engineering friends out there:.
0
0
10
@eversinc33 @C5pider Side note: Unlike Trevor, 5pider is actually a very pretty boy in real life fr π³.
0
0
0