I decided to commit another part to the Applied Reverse Engineering series with an article diving into rolling your own primitive tracer for discrete purposes; coupled with an analysis on outrunning integrity checks.
If you want to learn reverse engineering but don't know assembly here's part 1 of my x86_64 Assembly crash course - Accelerated Assembly. Part 2 will be released soon, this post was getting increasingly packed!
We need less tech e-journals / “tech news curators” with incompetent owners/writers. It’s on par with the drivel and saturation of Podcasts these days. Where in this did Microsoft say they are removing kernel access for 3rd parties? Where in their official statement? Their
It's been a while... here's the next part of the MMU virtualization series covering some paging details, MTRR basics, and constructing an EPT hierarchy.
Unlock forbidden Windows knowledge! 🤫💻
Find the PEB through truly undetected means and pop calculator 💥
The non-golf form will be available below 👇
#redteamtips#windowsinternals#rust
As promised, an introduction to virtualization and the true beginning of understanding and writing your own hypervisor.
Day 1 is out. 5 more to go and, if you're following along, you'll have control over your own virtual machine.
I got time to update a draft that should've been published long ago. Here is a fun PG-compliant hooking mechanism, and the example covered in the article is system-wide SYSCALL hooks in a PG-compliant manner.
I've published the 3rd article in the Applied Reverse Engineering series covering the low-level details of exceptions and interrupts, and some leads to getting started with abusing SEH.
revers.engineering/applied-re-exc…
Pleased to announce my latest series - Applied Reverse Engineering. This series is designed to help those interested in learning how to reverse engineer software. I've published the first two articles along with the index.
revers.engineering/applied-revers…
I mean to be fair I think kernel mode anti cheat is a bad software pattern. It puts an unnecessary amount of risk in the kernel, for no meaningful reason. But I hear what you’re saying.
Part 2 of Accelerated Assembly. Take a real target and learn more assembly in the deep end (without your floaties). Learn various techniques to make analysis easier, and hopefully, inspire you to go out on your own!
It's been a long time coming, but I'm publishing the first two parts of the EPT series. I will update this thread with links to the posts as I publish them. They're long, but hopefully comprehensive enough for even the most unfamiliar to implement EPT.