Another way to view kernel memory is with a graphical when debuging the kernel. You can find KReClassEx in my Gitub repository. github.com/BeneficialCode…
When I was a colleage student, I was so poor that I only use some cracked tool, such as IDA Pro. If I have the ability to purchase a license, I will do it. Because I know that developing a stable software is a not easy thing.
Search assemble signature in the kernel then detect the inline hook, although there is patch guard in x64. But I'm only for fun.
github.com/BeneficialCode…
The sixth article in the Malware Analysis Series (MAS) is available:
exploitreversing.com/2022/11/24/mal…
The C2 configuration extractor is slightly less trivial than expected.
Thank you @ilfak and @HexRaysSA for supporting and providing me with IDA Pro.
#malwareanalysis #malware
19 Followers 1K FollowingSeek and destroy threats | I will find your malware and take down it | DM for Study together | I do not use Twitter so much | him, his | @Intelis_ABIN Agent/SEC
2K Followers 1K FollowingDebug Engineer.
Windows, drivers and all things kernel mode.
I express my views, not my employer's. My views are my own and just my personal opinions.
8K Followers 6K FollowingDiagnostician. Author of Diagnomicon. Gang of One. Software Surgeon. Machine Learning and AI for Software Diagnostics and Observability. Generative Debugging.
26K Followers 1K FollowingI play with vulnerabilities and exploits. I used to be here on Twitter but now I'm here:
@[email protected]
https://t.co/hXggdAVkSQ
2K Followers 1K FollowingDebug Engineer.
Windows, drivers and all things kernel mode.
I express my views, not my employer's. My views are my own and just my personal opinions.
89K Followers 75 FollowingHi! I'm Dave Plummer. You might remember me from such Windows components as Task Manager, Windows Pinball, Calc, ZIPFolders, Product Activation, etc. Cheers!
1K Followers 352 FollowingMSFT, author of Advanced Windows Debugging and Advanced .NET Debugging, lead the Sysinternals team.
Active on https://t.co/lJSa9FdltV
62K Followers 286 FollowingA kiwi coding mimikatz & kekeo
github: https://t.co/eS3LVgU6i0
Head of security services @banquedefrance
Tweets are my own and not the views of my employer
4K Followers 762 FollowingSecurity Research PM at @Microsoft, Passionate about #hacking, #security and #powershell, tweets are my own | @[email protected]
15K Followers 521 FollowingRE and More by Alexey Kleymenov (https://t.co/s1pWjL46AW). Private classes and group workshops in malware analysis and reverse engineering. #infosec #malware
849 Followers 385 FollowingFounded @M2TeamOfficial. Author of NanaZip and NanaBox. Microsoft MVP (DT & WD). Research Windows user mode and Hyper-V guests as hobbies. Opinions are my own.
8K Followers 6K FollowingDiagnostician. Author of Diagnomicon. Gang of One. Software Surgeon. Machine Learning and AI for Software Diagnostics and Observability. Generative Debugging.
8K Followers 278 FollowingOS/systems engineer. Worked on WinDbg for a while. I write about low level tech sometimes.
On bluesky: @timdbg.com
On mastodon/fediverse: @[email protected]
49K Followers 339 FollowingSecurity researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc. Mastodon: @[email protected]
13K Followers 1K Followingzero-fucks-given infosec research | contacts: https://t.co/AB3QnrPja0 | 🇺🇦 Ukraine needs your help to kill Ruϟϟian zombies: https://t.co/58pTGiK8iv