Hexacorn

@hexacorn.bsky.social

Red Brain, Blue Fingers Malware Analysis, Reverse Engineering, Threat Hunting, Detection Engineering, DFIR, Security Research, Programming, Curiosities, Software Archaeology, Puzzles, Bad dad jokes https://www.hexacorn.com/blog/ hexacorn@infosec.exchange

@hexacorn.bsky.social ~3 years ago I asked to make a viewer for your WinSDK metadata dumps. Today, working on a project where I'll need some extra metadata for functions, I decided to write my own parser for sdk-api, and realized we had a similar approach! Full circle github.com/cristeigabri...

GitHub - cristeigabriela/sparse: Parse Microsoft' Windows SDK API documentation (MSDN) fast, and locally! Export to stable JSON format.

Parse Microsoft' Windows SDK API documentation (MSDN) fast, and locally! Export to stable JSON format. - cristeigabriela/sparse

github.com

less known way to calculate sha256 of files on Windows disksnapshot -c -k -v c:\test will print out file info including sha256 for every file in the directory

Bild

'One Battle After Another' and 'Frankenstein' brought my wife and I back to the cinema in recent weeks and it was totally worth it. Nothing beats the experience of a full immersion that only cinema can deliver. It helps that both movies are long.

Close your eyes and ✨imagine: From a low-integrity process (from LPAC even), you can inject your data anywhere you want: privileged tasks, PPL/protected processes, the OS kernel itself, and VTL1 trustlets. Now open your eyes. It is not hypothetical. It is the reality. Read it on page 33.

Paged Out!@pagedout.bsky.social · 10mo ago

pagedout.institute ← we've just released Paged Out! zine Issue #7 pagedout.institute/download/Pag... ← direct link lulu.com/search?page=... ← prints for zine collectors pagedout.institute/download/Pag... ← issue wallpaper Enjoy! Please please please share to spread the news - thank you!