Sign in

diversenok

@diversenok.bsky.social
26 followers 10 following 7 posts

Aspiring Windows security researcher & system programmer; student. GitHub: github.com/diversenok

PostsRepliesMedia
diversenok @diversenok.bsky.social · 14/08/2026
New blog post: "On COM/WinRT Initialization, Apartments, and lpacCom Capability Bypasses, Part 1" The series discusses a capability that restricts COM usage in a Less Privileged AppContainer sandbox and what we can learn from it about COM internals 💡 www.huntandhackett.com/blog/lpaccom...
huntandhackett.com
On COM/WinRT initialization, apartments, and lpacCom capability bypasses, Part 1
Explore the intricacies of COM/WinRT initialization, component activation, and capability checks in sandboxed environments, focusing on LPAC bypass techniques.
010
diversenok @diversenok.bsky.social · 10/11/2025
I wanted to understand what information is available in .pdb files, so I made a tool for it 🔎🐛 Welcome DiaSymbolView - a debug symbol hierarchy and properties viewer based on MSDIA: github.com/diversenok/D...
A screenshot of DiaSymbolView inspecting combase.pdb
1104
diversenok @diversenok.bsky.social · 30/09/2025
Here are my RomHack slides about low-privileged attack vectors against PsSetLoadImageNotifyRoutine and drivers that rely on it. Enjoy! diversenok.github.io/slides/RomHa...
Attacking Assumptions Behind the Image Load Callback :: RomHack 2025
021
diversenok @diversenok.bsky.social · 15/05/2025
My new blog post 🥳 Improving AFD Socket Visibility for Windows Forensics & Troubleshooting It discusses the low-level API under Winsock (IOCTLs on \Device\Afd handles) and explores the workings of the new socket inspection feature in System Informer 🔥 www.huntandhackett.com/blog/improvi...
huntandhackett.com
Improving AFD Socket Visibility for Windows Forensics & Troubleshooting
This blog post explains the basics of Ancillary Function Driver API and how it can help explore networking activity on Windows systems.
021
diversenok @diversenok.bsky.social · 18/04/2025
I think the list of unloaded modules (aka. RtlGetUnloadEventTraceEx) is underappreciated. Ntdll records metadata about DLLs that unloaded from the process and even includes modules that attempted to load but failed their DllMain. learn.microsoft.com/en-us/window...
010
diversenok @diversenok.bsky.social · 07/04/2025
The feature is live in the latest Canary builds and displays even more properties than initially planned 😍 Also, a blog post that explains the basics of AFD API and its forensic potential is coming soon.😉
010
diversenok @diversenok.bsky.social · 25/03/2025
Better socket handle visibility coming soon to System Informer! 🔥 When viewing a process handle table, SI will recognize files under \Device\Afd and retrieve information about their state, protocol, addresses, and more. Also works on Bluetooth and Hyper-V sockets 🤩
010