Log inSign up
Alisa Esage Шевченко
5,393 posts
user avatar
Alisa Esage Шевченко
@alisaesage
Independent hacker and researcher, owner of Zero Day Engineering @zerodayalpha
hyperspace
alisa.sh
Joined July 2011
99
Following
40.7K
Followers
  • Pinned
    user avatar
    Alisa Esage Шевченко
    @alisaesage
    Jan 17, 2025
    Understand Assembly low-level programming in 22 minutes youtu.be/DWkImpawzhc I remember how it clicked for me. This video shows what I saw, illustrated with examples from all the mainstream CPU architectures
    52K
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Apr 8, 2021
    Official: I won Pwn2Own competition in the Virtualisation category. It’s an essential milestone in a professional hacker’s career, and a major goal personally. I am super hyped! And relieved Details of the exploit that I developed are now under embargo of responsible disclosure
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Apr 20, 2024
    Just gave a new life to my 11-year old vintage MacBook Pro! Not many people realise that battery aging is no.1 reason of dying older laptops. And it’s easy to replace Thread with my tips
    Image
    228K
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Apr 8, 2021
    Not bad for the first girl at Pwn2Own
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Nov 22, 2024
    Releasing full 2+hr video of my browser exploitation workshop from VXCON 2024: youtube.com/live/b9OhamkAY… In which I show what goes inside the mind of a skilled hacker while exploiting a highly non-trivial vulnerability in v8, from zero to exploit concept. Especially this workflow
    41K
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Mar 23, 2024
    It took 3 years but finally I feel ready to release my Pwn2Own 2021 exploit code. 💖 Video talk covers my full research workflow, from attack surface modeling and reverse engineering, to vulnerability discovery and systematic exploit engineering, enjoy! #Pwn2Own
    user avatar
    Zero Day Engineering
    @zerodayalpha
    Mar 23, 2024
    Release: VM Escape Exploit for Parallels Desktop Hypervisor (Pwn2Own 2021) zerodayengineering.com/research/pwn2o… A virtual machine escape exploit will typically require kernel privileges in the guest OS. In this exploit I chose to offload the reverse-engineered toolgate protocol
    163K
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Apr 24, 2021
    While my Pwn2Own exploit is in the patching, I wanted to share a trivial *no-bug, by-design* full VM escape with persistence PoC for latest Parallels Desktop on Intel and M1. I hope it will wake up a person or two Writeup: zerodayengineering.com/blog/dont-shar… Code: github.com/badd1e/Proof-o…
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Apr 18, 2021
    I’m thinking about it. “Zero Day Engineering for beginners” training
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    May 31, 2019
    Replying to @alisaesage
    Remote code execution vulnerability in most recent versions of the nginx web server. Pending responsible disclosure via Zero Day Initiative and the nginx team
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Nov 14, 2020
    Slides: "Hypervisor Vulnerability Research: State of the Art" (with a deep focus on Hyper-V & ESXi) alisa.sh/slides/Hypervi…
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Jan 29, 2022
    I invested two decades of life into reverse-engineering and hacking man-made systems down to bits. Today I can pwn anything that has software in it, in a predictable time. It’s not a challenge anymore… What if you apply those skills to the most fundamental of God-made systems?
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Oct 9, 2023
    Think of it as my kitchen 💅
    Image
    00:00
    46K
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Mar 17, 2022
    Nice little-known writeup on WhatsApp exploitation: awakened1712.github.io/hacking/hackin… < technically interesting for more than one reason
    Image
    awakened1712.github.io
    How a double-free bug in WhatsApp turns to RCE
    In this blog post, I’m going to share about a double-free vulnerability that I discovered in WhatsApp for Android, and how I turned it into an RCE. I informed this to Facebook. Facebook acknowledged...
  • user avatar
    Alisa Esage Шевченко
    @alisaesage
    Mar 16, 2018
    Got my 1st VM escape vulns in @Oracle VirtualBox, via unprivileged guest to hypervisor on the host. A little late for #pwn2own... Still a personal record: one month from zero (knowledge about the target) to zero (day). VirtualBox is nice and well-designed, I enjoyed looking at it
    Image
    Image

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement