matterpreter Profile Banner
Matt Hand Profile
Matt Hand

@matterpreter

Followers
10K
Following
2K
Media
36
Statuses
861

Director, Security Research @preluderesearchšŸ’œ | Author of Evading EDR https://t.co/E5fs0sSTOv šŸ“– | Adversary tradecraft & windows internals 🦠

USA
Joined June 2010
Don't wanna be here? Send us removal request.
@matterpreter
Matt Hand
2 years
I've long been interested in how EDRs work under the hood and how we can apply a more evidence-based approach to evasion. I'm happy to announce that I've written a book covering these topics with @nostarch which is now available for preorder šŸŽ‰.
Tweet card summary image
nostarch.com
A guide to understanding the attack-detection software running on Microsoft systems, and how to evade it.
46
334
1K
@matterpreter
Matt Hand
12 days
RT @PreludeResearch: Join us in Islander E-I for @33y0re’s talk on KCFG AND KCET internals #BHUSA . .
0
3
0
@matterpreter
Matt Hand
12 days
I’ll be around all day so come say hi if you see me! I’m hiring security researchers and developers.
Tweet card summary image
jobs.ashbyhq.com
SOFTWARE ENGINEER ABOUT PRELUDE Prelude is a small team of security researchers and software developers working to reinvent the way we protect endpoints in a world where threats are complex, emerge...
@PreludeResearch
Prelude Research
12 days
See you tomorrow at #BHUSA .
Tweet media one
0
3
18
@matterpreter
Matt Hand
19 days
Two years ago, I left red teaming for a new challenge in endpoint security. I'm humbled by the incredible team we've built and so proud to share this research preview of our work. It’s an idea I believe in deeply, and I can’t wait for what’s ahead. šŸ–¤.
@PreludeResearch
Prelude Research
19 days
Announcing our whitepaper on the future of endpoint security.
4
24
177
@matterpreter
Matt Hand
3 months
RT @33y0re: I am excited to say my talk at @BlackHatEvents USA 2025 was accepted where I will be sharing my recent research on kernel-mode….
0
24
0
@matterpreter
Matt Hand
4 months
RT @0xdab0: RUST WINDOWS DOCS MCP. If you've ever done Rust dev with the windows crate, you know it's painful because it makes up API calls….
0
5
0
@matterpreter
Matt Hand
4 months
We're also looking for software engineers to join the team. Rust and Windows development experience are a strong plus. US/Canada preferred but willing to flex for the right person.
0
1
9
@matterpreter
Matt Hand
5 months
The team at @PreludeResearch is looking for Windows internals researchers, reverse engineers, and people passionate about rethinking how we combat modern adversaries. Join us!
1
9
49
@matterpreter
Matt Hand
6 months
RT @33y0re: Today I’m sharing a blog post on the implementation of kernel mode shadow stacks on Windows! This post covers actively debuggin….
connormcgarr.github.io
Using SourcePoint’s JTAG debugger to investigate the implementation of Intel CET Shadow Stacks in kernel-mode on Windows
0
154
0
@matterpreter
Matt Hand
9 months
We’re going to start doing some more informal hangouts in our @discord server and figured we’d host the first as everyone starts winding down for the year. I hope you can join us to talk shop and share what youve learned this year šŸ™.
@preludeorg
Prelude
9 months
Former offsec operator and author of "Evading EDR," @matterpreter has seen the development of how organizations evaluate defenses 🪓. Join us on Dec 17 @ 1 ET for a retrospective on his experience, his book, and the evolution of #controlvalidation.
Tweet media one
0
0
8
@matterpreter
Matt Hand
9 months
This year's bundle has an amazing selection and I'm so excited to see Evading EDR included. If you haven't picked up a copy, now is a great time to get one šŸŽ.
@nostarch
No Starch Press
9 months
18 hacking books. Name your price. Our Hacking 2024 @humble bundle is now LIVE. Support @ACLU & @EFF while leveling up your security game. #CyberMonday
Tweet media one
2
10
50
@matterpreter
Matt Hand
9 months
RT @clintgibler: šŸ”¬ Applying Test-Driven Development to Detection Engineering. @matterpreter describes applying TDD principles to detection….
0
7
0
@matterpreter
Matt Hand
10 months
RT @preludeorg: It's time to overcome manual efforts when it comes to purple teaming🚫. Next week—join @matterpreter at the @SANSInstitute….
0
1
0
@matterpreter
Matt Hand
10 months
RT @preludeorg: Test-driven development—not just for software engineering. @matterpreter breaks down how applying this logic streamlines….
0
6
0
@matterpreter
Matt Hand
10 months
RT @33y0re: I am very happy to have presented my talk "Redefining Security Boundaries: Unveiling Hypervisor-Backed Security Features For Wi….
Tweet card summary image
github.com
Contribute to connormcgarr/Presentations development by creating an account on GitHub.
0
41
0
@matterpreter
Matt Hand
10 months
RT @aall86: Here you go. Italian trip gift :-) @_0xDeku, @yarden_shafir and the others. .
0
17
0
@matterpreter
Matt Hand
10 months
So pumped to have Max on the teamšŸ˜ˆšŸ–¤.
@0xdab0
Max Harley
10 months
It's been a wild couple weeks (travel + hurricane) and I meant to do this sooner. Today was my first day at @preludeorg! Really pumped to be working with these guys.
1
0
12
@matterpreter
Matt Hand
11 months
RT @tifkin_: Really happy to see that Ghidra 11.2 has a built-in option for VS code now. Checkout the Ā VSCodeProjectScript script to set i….
0
10
0
@matterpreter
Matt Hand
11 months
RT @preludeorg: When security teams need certainty, opaque logic stands in the way of understanding how their #EDRs respond to threats. Wha….
0
2
0