Stephen Sims (@steph3nsims) 's Twitter Profile
Stephen Sims

@steph3nsims

Perpetual Student | SANS Fellow | Musician | Braggart Hater | Gray Hat Hacking | VR | 🏂 | deadcode | youtube.com/@OffByOneSecur…

ID: 2332293343

linkhttp://deadlisting.com calendar_today07-02-2014 19:10:41

3,3K Tweet

23,23K Followers

815 Following

Stephen Sims (@steph3nsims) 's Twitter Profile Photo

People often ask about how windows Kernel memory allocations work ever since the introduction of the segment heap into ring 0.

Ayla Croft (@aylacroft) 's Twitter Profile Photo

Got my ticket, hotel & flight booked for DEF CON Last year was my 1st time, thanks to winning a free trip via Stephen Sims & Off By One Security members. Thanks to that trip, I was able to land my 1st cybersecurity job & now they're sending me this year!

Stephen Sims (@steph3nsims) 's Twitter Profile Photo

If there's interest I was thinking about doing a stream for an hour this Friday while I'm teaching a class on introductory Windows exploit development. Next Friday I'm hoping to continue turning the recent patch diff we did on ole32.dll into a crash condition PoC.

Linux Kernel Security (@linkersec) 's Twitter Profile Photo

Fuzzing Linux Kernel Modules, with Slava Moskvin Stream by Slava Moskvin | Path Cybersec hosted by Stephen Sims about building a custom fuzzer to rediscover CVE-2025-0927 in the HFS+ filesystem implementation. youtube.com/live/uCcsZrXyL…

Stephen Sims (@steph3nsims) 's Twitter Profile Photo

I will be streaming a portion of the SANS SEC660 course I'm teaching today in DC on Introduction to Windows Exploit Development. We will use ROP to get around DEP on Windows 11. 1PM PT youtube.com/watch?v=cbIEwz…

Stephen Sims (@steph3nsims) 's Twitter Profile Photo

Join me this Friday at 11AM PT on the Off By One Security stream with the team from dreadnode for a session on "Building and Deploying Offensive Security Agents!" youtube.com/live/BzOmGw-La…

Join me this Friday at 11AM PT on the <a href="/offby1security/">Off By One Security</a> stream with the team from <a href="/dreadnode/">dreadnode</a> for a session on "Building and Deploying Offensive Security Agents!" 

youtube.com/live/BzOmGw-La…
Stephen Sims (@steph3nsims) 's Twitter Profile Photo

Thanks to the team dreadnode for joining me for an informative stream today! You can watch the recording on YouTube here: youtube.com/watch?v=BzOmGw… Off By One Security

Off By One Security (@offby1security) 's Twitter Profile Photo

We're almost at 30K subscribers on YouTube, have over 100 videos, passed 50K hours watched, and are up to 21 members! Please consider helping us to promote the channel to get a wider reach! All proceeds go back to the community! youtube.com/@OffByOneSecur…

flux (@0xfluxsec) 's Twitter Profile Photo

Introducing: Hells Hollow - Thought rootkit SSDT hooking was dead? Following my previous work, I have managed to essentially reintroduce SSDT hooks, capable of modifying the *original* KTRAP_FRAME and more! Whitepaper: fluxsec.red/hells-hollow-a… #infosec #cybersecurity

Introducing: Hells Hollow - Thought rootkit SSDT hooking was dead? Following my previous work, I have managed to essentially reintroduce SSDT hooks, capable of modifying the *original* KTRAP_FRAME and more!

Whitepaper: fluxsec.red/hells-hollow-a…

#infosec #cybersecurity
Stephen Sims (@steph3nsims) 's Twitter Profile Photo

The heavily updated version of the Advanced Exploit Dev course "SEC760" with my coauthor Alexandre Becholey was just recorded and available at sans.org/sec760 Updates include Linux Chrome V8 Exploitation, IDA 9.1, Kernel Debugging Windows Mitigations, 2025 patch diffs, etc...

Natalie Silvanovich (@natashenka) 's Twitter Profile Photo

While most vendors ship timely patches for vulnerabilities reported by Project Zero, they don’t always reach users. Today, we’re announcing Reporting Transparency, a new policy to encourage downstream fixes googleprojectzero.blogspot.com/2025/07/report…