
Jiří Vinopal
@vinopaljiri • 10,534 subscribers
Security Researcher at @_CPResearch_ All opinions expressed here are mine only. https://t.co/bNWc3k9HwF
Videos

Currently completing some pretty cool offensive .NET internals research (redacted for now...)🔥 Call me too excited, but I think this one's legit top-tier 🙃 I am super curious about your opinion → Vote below please 🤔 Quick teaser ➡️ Clean .NET sample vs technique applied, side by side in the latest #dnSpyEx: ✅ Clean: • Breakpoints fired • Break on Module/Assembly (Dynamic/Reflection) Load fired • Modules visible • Dynamic analysis intact ❌ Real PoC: • Empty module list • No Breakpoints fired • No Assembly/Module load events - ever • ETW (logman, PerfView) → completely silent • .NET profiler API (e.g. dotTrace) → native-only, managed code gone Managed runtime? ➡️ Unaffected (normal execution) Observers? ➡️ Totally deaf .NET PE Dynamic analysis ➡️ Dead, no ETW, no Managed debugger, no .NET profiler! Write-up coming. Am I too excited or does this slap? 👇 #dotnet #CLR #threatresearch #malware #exploit
Jiří Vinopal12,100 Aufrufe • vor 2 Monaten

Let's Zoom-In to the new start of the week... 🔍 Releasing #IDA Plugin #ZoomAllViews — Ctrl+Scroll font zoom for every IDA view. 💪 Because this should work out of the box. Now it does. 🤓 • Zoom in/out in Disassembly, Pseudocode, Hex View, Strings, Imports, Functions, Structures, and every chooser 😲 • Works across Normal & Debug view widgets — Stack, Registers, Locals, Watch • Row heights scale automatically with font size • Graph/Proximity/Xref views excluded — IDA's native zoom untouched ☝️ • Toggle on/off via menu or Ctrl-Shift-Z • Single file, zero dependencies 🫰 • Compatible IDA 8.x — 9.3+ (PyQt5 / PySide6) 🛠️ #IDAPro #ReverseEngineering #IDAPython #Malware #DFIR Hex-Rays SA
Jiří Vinopal14,337 Aufrufe • vor 3 Monaten

#IDA TIP to load #Windows #Kernel types: [1/2] Windows Kernel types (e.g., EPROCESS, ETHREAD, etc.) are not a part of the built-in IDA TILs (because they are changing across different WIN versions). 1. These types are a part of the "ntoskrnl.exe" debug symbols -> "ntkrnlmp.pdb". 2. IDA supports loading "only types" from arbitrary "pdb" file. 3. One can also use the IDA->File->Load file->PDB file dialog to load specific version of "ntoskrnl.exe" and IDA will proceed with automatic download of appropriate "ntkrnlmp.pdb" applying "only types" (if optional checkbox is selected). 4. See example video...
Jiří Vinopal21,744 Aufrufe • vor 1 Jahr
Keine weiteren Inhalte verfügbar