
tsunekoh
@tsunek0h
Followers
605
Following
4K
Media
22
Statuses
335
Security Researcher, macOS, Arm-based Windows, @[email protected]
Joined May 2018
🎉 My submission for Black Hat USA (@BlackHatEvents #BHUSA) has been accepted!. I will talk about reverse engineering results of XProtect Remediator (XPR). XPR doesn’t just scan files using YARA rules and delete malware — it does a lot more! It uses a creative mechanism that
7
10
81
RT @theevilbit: Apple failed to fix this so many times. I first reported this back in macOS Big Sur, and it's literally detailed in my EXP-….
0
36
0
My dream came true!.My submission for #OBTS has been accepted! I’ll be talking about the internals of XProtect Remediator, including its detection logic and the DSL implemented using Swift result builders. To be honest, there are many veteran researchers on the list, so I’m.
📢 Just dropped: the full #OBTS v8 talk lineup! And for the first time we'll have 3 full days of presentations! 🤩. Congrats to the selected speakers and mahalo to all who submitted. With ~100 submissions, selecting the final talks was a daunting task! 😫.
4
6
51
RT @objective_see: 📢 Just dropped: the full #OBTS v8 talk lineup! And for the first time we'll have 3 full days of….
objectivebythesea.org
Conference Talks
0
26
0
My submission for #NullconBerlin2025 has been accepted! I will talk about the details of CVE-2025-24204, which breaks process isolation on macOS.
2
8
56
RT @patrickwardle: ⏳ Just one week left to submit your talk to #OBTS v8 .(CFP closes June 30th). We’ve expanded to….
objectivebythesea.org
Submit a talk for #OBTS today!
0
15
0
RT @karmaz95: Think RAM forgets? 🤔 Not always. See how secrets can leak, what mitigations exist on major OS like #macOS, #Windows, #Linux,….
afine.com
This article explores a security flaw in desktop applications across Windows, Linux, and macOS: the persistent storage of sensitive data in memory.
0
6
0
RT @MacDevOpsYVR: 🥰 Thanks for an awesome talk @theevilbit on finding vulnerabilities in Apple packages at scale (using AI) at MDO YVR 2025….
0
1
0
RT @PhorionTech: Introducing Phorion. A modern EDR platform purpose-built for macOS. Because security teams shouldn’t have to settle for Wi….
0
7
0
RT @jbradley89: My next book is open for pre-orders!!!. I have included the first two chapters in audiobook form for free. You can listen t….
themittenmac.com
https://youtu.be/OnIAmOz0TjoChapter 1https://youtu.be/9bQCWbe2kDwChapter 2Preorders Now AvailableOver the past year, I’ve been hard at work writing Threat Hunting ma
0
32
0
RT @InfPCTechStack: Our talk at #BHUSA @BlackHatEvents Briefings has been accepted!. This is a presentation on an initiative to make the BI….
0
11
0
RT @InvokeReversing: We're excited to announce the release of BinjaLattice MCP! With this, you can reverse engineer binaries with Binary Ni….
0
40
0
RT @Technologeeks: Get unparalleled depth on #Scudo Memory allocator internals - AND a sneak peek at @Morpheus______'s surprise new book -….
0
7
0
RT @MsftSecIntel: Microsoft Threat Intelligence has uncovered a new variant of XCSSET, a sophisticated modular macOS malware that targets u….
0
120
0
RT @0xjprx: When the kernel is sus. CVE-2024-54507 is an XNU bug fixed in macOS 15.2 / iOS 18.2. Enjoy!.
jprx.io
A very sus sysctl in the XNU kernel.
0
26
0