Yarden Shafir (@yarden_shafir) 's Twitter Profile
Yarden Shafir

@yarden_shafir

A circus artist with a visual studio license

ID: 957698274324074496

linkhttps://github.com/yardenshafir calendar_today28-01-2018 19:33:56

7,7K Tweet

23,23K Followers

303 Following

Andrea Allievi (@aall86) 's Twitter Profile Photo

techcommunity.microsoft.com/blog/windows-i… Finally! I personally worked on Hotpatch, together with my team 3 years ago... and now is finally approaching client versions of Windows... Yuuuyuuu!

Synacktiv (@synacktiv) 's Twitter Profile Photo

PagedOut! #6 magazine is out! This edition features two articles from our ninjas: - Implicit Unicode behaviors in database string functions - Calling Rust from Python: A story of bindings Dive into their insights here: pagedout.institute

chompie (@chompie1337) 's Twitter Profile Photo

If you ever think there are no more bugs left to find… this Linux kernel bug was just patched yesterday and existed for 5 YEARS

If you ever think there are no more bugs left to find… this Linux kernel bug was just patched yesterday and existed for 5 YEARS
Yoni Rozenshein (@1yoni) 's Twitter Profile Photo

This morning at #BlueHatIL - Yarden Shafir opens Event Viewer, finds 6 CVEs :) Also reminds us that RPC is always an interesting attack surface. Great talk! šŸ”„

This morning at #BlueHatIL - <a href="/yarden_shafir/">Yarden Shafir</a> opens Event Viewer, finds 6 CVEs :)

Also reminds us that RPC is always an interesting attack surface.
Great talk! šŸ”„
Mathilde Venault (@mathildevenault) 's Twitter Profile Photo

Really excited to give a talk at SINCON this year! I'll be presenting my tool github.com/CrowdStrike/dr…, that helps making the most of WinDbg in a minimum amount of time

Mari0n (@pinkflawd) 's Twitter Profile Photo

Ill be teaching a 4-day Linux Malware Reverse Engineering training at Recon this year, so psyched 😱 recon.cx/2025/training.…

Satoshi Tanda (@standa_t) 's Twitter Profile Photo

I am thrilled to be back and offer the in-person training once again at Hexacon, the fabulous conf. in Paris hexacon.fr/trainer/tanda/ Get hands-on experience with virtualization and learn real-world applications and bugs of them! The tickets will be available for purchase soon.

William R. Messmer (@wmessmer) 's Twitter Profile Photo

If you update WinDbg today (1.2504.15001.0), you might notice another icon in the View tab of the ribbon, one called "Parallel Stacks". While incredibly useful in its own right, this isn't just a parallel stacks view. It's the introduction of graph visualization for extensions!

If you update WinDbg today (1.2504.15001.0), you might notice another icon in the View tab of the ribbon, one called "Parallel Stacks".  While incredibly useful in its own right, this isn't just a parallel stacks view.  It's the introduction of graph visualization for extensions!
b33f | šŸ‡ŗšŸ‡¦āœŠ (@fuzzysec) 's Twitter Profile Photo

I'm reposting my IBM blog dealing with Lazarus and "Direct kernel object manipulation (DKOM) attacks on ETW providers" on knifecoat šŸ”ŖšŸ§„ knifecoat.com/Posts/Direct+K…

I'm reposting my IBM blog dealing with Lazarus and "Direct kernel object manipulation (DKOM) attacks on ETW providers" on knifecoat šŸ”ŖšŸ§„

knifecoat.com/Posts/Direct+K…
Michael Maltsev (@m417z) 's Twitter Profile Photo

Windhawk was just updated with ARM64 support! ramensoftware.com/windhawk-v1-6-… Making it work took more than just compiling it for ARM64, as the image below illustrates, and resulted in the following side projects: • MinHook-Detours. • wow64pp-x64-arm64 (Heaven’s Gate). Info, links: ...

Windhawk was just updated with ARM64 support!
ramensoftware.com/windhawk-v1-6-…
Making it work took more than just compiling it for ARM64, as the image below illustrates, and resulted in the following side projects:
• MinHook-Detours.
• wow64pp-x64-arm64 (Heaven’s Gate).
Info, links: ...
Yarden Shafir (@yarden_shafir) 's Twitter Profile Photo

In this most recent phase of Microsoft hating its users, shared OneDrive folders can't be accessed locally anymore. A link is just a url link, with no local access whatsoever. This has been as issue for a year now, with no response from Microsoft: reddit.com/r/Office365/co…

K runs on corn juice (@turb0yoda) 's Twitter Profile Photo

I got hit with the CRWD RIF. Looking for any DFIR Consulting or SecEng-ish role.. Been doing DFIR for 5 years both at CRWD and at Cylance- I can provide references and resume on request.

Yarden Shafir (@yarden_shafir) 's Twitter Profile Photo

FYI if you’re willing to link with ntdll or dynamically resolve it there’s a ton of APIs that return TEB/PEB or leave them in one of the registers. (Don’t believe official return values. MSDN is a liar!)

FYI if you’re willing to link with ntdll or dynamically resolve it there’s a ton of APIs that return TEB/PEB or leave them in one of the registers.
(Don’t believe official return values. MSDN is a liar!)