|
Alex Ionescu
@
aionescu
Seattle, WA
|
|
Windows Internals Expert, Speaker, Trainer and Security Researcher. He/Him. RTs are not endorsements, opinions are my own.
|
|
|
6.650
Tweetovi
|
1.608
Pratim
|
36.398
Osobe koje vas prate
|
| Tweetovi |
|
Alex Ionescu
@aionescu
|
23 h |
|
Windows has mitigations to limit any impact for security sensitive situations and introduces security domains.
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
4. velj |
|
XP logical prefetch only used 10 seconds. Vista Superfetch monitors continuously.
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
4. velj |
|
1) Dangerous, unsafe levels of scotch consumption.
2) ADHD Brain
3) Sushi
|
||
|
|
||
| Alex Ionescu proslijedio/la je tweet | ||
|
Yarden Shafir
@yarden_shafir
|
3. velj |
|
Me too 😅
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
3. velj |
|
|
||
|
Alex Ionescu
@aionescu
|
3. velj |
|
I’ve taken a look, her brain basically kind of looks like this pic.twitter.com/fC5vVhHb1r
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
3. velj |
|
After this and the CET paper, I realized it's so much nicer to write blog posts when someone can do the research with you! Between the content on Errata Manager, ACPI, Kernel LFH/VS Heap, and Windows Defender we have in various unfinished states, I hope we don't forget Part 2😅
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
3. velj |
|
Here's some research @yarden_shafir and I did based on a question I got in our Windows Internals course a few weeks ago. Whenever I tell people that I learn a lot from people's questions when *teaching* the course, they think it's a generic modest "feel good" answer. It's not 😊 twitter.com/yarden_shafir/…
|
||
|
|
||
| Alex Ionescu proslijedio/la je tweet | ||
|
Yarden Shafir
@yarden_shafir
|
2. velj |
|
Can your EDR detect symbolic link callback rootkits? Because ours sure as heck can't.
@aionescu and I wrote about these!
windows-internals.com/dkom-now-with-…
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
1. velj |
|
Yep, the usual is to send an email one week ahead: 1) once the final attendee list is confirmed and received by the trainers from the conference (which usually happens ~10 days before the course) 2) once all the tools, headers and builds have come out on Wednesday/Friday
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
31. sij |
|
Windows 10 19555: "MiMirrorBlackPhase". Can't tell if someone's a fan of #BlackMirror or if this is yet another thing Justin Trudeau is up to.
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
27. sij |
|
Looks Thai or Cambodian
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
22. sij |
|
In the Windows case there are APIs for this
|
||
|
|
||
| Alex Ionescu proslijedio/la je tweet | ||
|
Saar Amar
@AmarSaar
|
21. sij |
|
In those CET times: It's possible to return in unwinding to any address in the SSP, causing a "type confusion" between stack frames ;)
I really like the different variants of this concept twitter.com/AmarSaar/statu…:) Type confusions are on fire! (stack frames, objc for PAC bypass) twitter.com/yarden_shafir/…
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
22. sij |
|
EVERYTHING? Even the buggy one that gives you AR?
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
22. sij |
|
VmSvcExt in scope or not?
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
20. sij |
|
If close to an office (there’s a big one in WA), people that need a bit more training and support are more than welcome to apply, we have a great onboarding process and team(s).
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
20. sij |
|
Security jobs @CrowdStrike for anyone interested in C/C++ kernel development and testing (user-mode too), especially if you're into the Linux/macOS threat landscape.
All global openings, not just US.
crowdstrike.wd5.myworkdayjobs.com/crowdstrikecar…
crowdstrike.wd5.myworkdayjobs.com/crowdstrikecar…
crowdstrike.wd5.myworkdayjobs.com/en-US/crowdstr…
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
20. sij |
|
Yes, @yarden_shafir and I will also be doing it at Recon in Montreal!
|
||
|
|
||
|
Alex Ionescu
@aionescu
|
20. sij |
|
The only right answer to “honey, I really hate Valentine’s Day and commercial couple stuff” is a ridiculously outrageous infosec party in Berlin. Can’t wait to see everyone at this awesome conference, the speaker lineup is amazing and the trainings are stellar! twitter.com/offensive_con/…
|
||
|
|
||