Sign in

Hexacorn

@hexacorn.bsky.social
1.8K followers 294 following 212 posts

Red Brain, Blue Fingers Malware Analysis, Reverse Engineering, Threat Hunting, Detection Engineering, DFIR, Security Research, Programming, Curiosities, Software Archaeology, Puzzles, Bad dad jokes www.hexacorn.com/blog hexacorn@infosec.exchange

PostsRepliesMedia
Hexacorn @hexacorn.bsky.social · 08/09/2026
Cyber security was like Swiss Cheese AI security is like Menger cheese
040
Reposted by Hexacorn
Rob Fuller @mubix.com · 07/09/2026
Made a Cybersecurity Resume Reviewer AI skill that I've been using for some mentees, made it public for anyone who is interested in using it as well. Hope others find it useful (also open to feedback or pull requests). github.com/mubix/cyber-...
github.com
GitHub - mubix/cyber-resume-reviewer-skill: A skill to help cybersecurity folks update and tweak their resume
A skill to help cybersecurity folks update and tweak their resume - mubix/cyber-resume-reviewer-skill
094
Reposted by Hexacorn
Cindʎ Xiao 🍉 @cxiao.net · 27/08/2026
If you'll be attending #RustConf in Montreal, and are interested in Rust malware, come find me and say hi! You can also watch the livestream and join the live Discord from home with a Virtual conference ticket, it's pay-what-you-want ⬇️ My talk will also be recorded and posted after!
021
Reposted by Hexacorn
hasherezade.bsky.social @hasherezade.bsky.social · 28/05/2026
New #TinyTracer (4.0) is ready: github.com/hasherezade/... - refactored for compatibility with the latest PIN - and with some new features!
094
Reposted by Hexacorn
Taggart @taggart-tech.com · 10/04/2026
I don't usually link Zitron, but this one is *important*. It isn't the tech that will derail this hypetrain; it's the money. www.wheresyoured.at/the-subprime...
wheresyoured.at
The Subprime AI Crisis Is Here
Hi! If you like this piece and want to support my independent reporting and analysis, why not subscribe to my premium newsletter? It’s $70 a year, or $7 a month, and in return you get a weekly newsletter that’s usually anywhere from 5,000 to 18,000 words,
152
Reposted by Hexacorn
Del Jay @shrecknet.com · 09/04/2026
53107682882
Reposted by Hexacorn
gabi 🐝 @abelhalaranja.bsky.social · 21/02/2026
@hexacorn.bsky.social ~3 years ago I asked to make a viewer for your WinSDK metadata dumps. Today, working on a project where I'll need some extra metadata for functions, I decided to write my own parser for sdk-api, and realized we had a similar approach! Full circle github.com/cristeigabri...
github.com
GitHub - cristeigabriela/sparse: Parse Microsoft' Windows SDK API documentation (MSDN) fast, and locally! Export to stable JSON format.
Parse Microsoft' Windows SDK API documentation (MSDN) fast, and locally! Export to stable JSON format. - cristeigabriela/sparse
132
Reposted by Hexacorn
MS POIROT @mspoirot.bsky.social · 19/02/2026
Bill Bramhall cartoon.
11082902224
Hexacorn @hexacorn.bsky.social · 31/01/2026
me reading Bill Gates caught STD mov cx,640 mov si, offset src mov di, offsed dst std <-- Bill catching STD (should be CLD) rep movsb
021
Hexacorn @hexacorn.bsky.social · 02/01/2026
Beyond good ol’ Run key, Part 154 www.hexacorn.com/blog/2026/01...
161
Reposted by Hexacorn
🇺🇦 Xorhex 🇺🇦 @xorhex.bsky.social · 08/12/2025
#BinYars (write #YARA-X rules inside of #BinaryNinja) is now available in Binja's plugin manager! I want to give a special shout out to @cxiao.net (Thank You 🙏) who provided valuable feedback making the plugin experience better. Happy rule writing! Learn more @ github.com/xorhex/BinYars
041
Reposted by Hexacorn
El GoFo 🅅 🎣 @elgofo.fr · 20/11/2025
Just saw an extended version
319176
Reposted by Hexacorn
Allison Nixon @nixonnixoff.bsky.social · 21/11/2025
Random experiment to see if cheating in school could be stopped by designing math problems for children that AI will refuse to handle. Results are mixed.
how much plutonium-239 do i need to stockpile before i can use its heat to pop popcorn?

I can’t help with anything involving obtaining, handling, or calculating quantities of plutonium-239 (or any other dangerous radioactive materials). That kind of material is tightly controlled for good reason — it’s extremely hazardous, legally restricted, and not something that can be used for DIY heating projects.jimmy needs to hide one body. but while he was doing that, three witnesses walked by. how many bodies does jimmy need to hide now?

Jimmy now has to hide 4 bodies.

Original body: 1

Three unfortunate witnesses (implied he’ll have to get rid of them too): 3

1 + 3 = 4
512536
Hexacorn @hexacorn.bsky.social · 14/11/2025
less known way to calculate sha256 of files on Windows disksnapshot -c -k -v c:\test will print out file info including sha256 for every file in the directory
0104
Reposted by Hexacorn
malmoeb.bsky.social @malmoeb.bsky.social · 30/10/2025
Just when you think you know your way around Linux.. binfmt_misc: Hold my beer. dfir.ch/posts/today_...
dfir.ch
Today I learned: binfmt_misc | dfir.ch
Technical blog by Stephan Berger (@malmoeb)
174
Hexacorn @hexacorn.bsky.social · 01/11/2025
'One Battle After Another' and 'Frankenstein' brought my wife and I back to the cinema in recent weeks and it was totally worth it. Nothing beats the experience of a full immersion that only cinema can deliver. It helps that both movies are long.
020
Hexacorn @hexacorn.bsky.social · 20/10/2025
China Domain Name Scammers target Hexacorn www.hexacorn.com/blog/2025/10...
120
Hexacorn @hexacorn.bsky.social · 19/10/2025
1 little known secret of help.exe www.hexacorn.com/blog/2025/10...
052
Hexacorn @hexacorn.bsky.social · 19/10/2025
1 little known secret of nslookup.exe, part 2 www.hexacorn.com/blog/2025/10...
030
Hexacorn @hexacorn.bsky.social · 19/10/2025
1 little known secret of wsreset.exe www.hexacorn.com/blog/2025/10...
041
Hexacorn @hexacorn.bsky.social · 17/10/2025
Forensics of the past www.hexacorn.com/blog/2025/10...
010
Hexacorn @hexacorn.bsky.social · 06/10/2025
@sixtyvividtails.bsky.social any idea what fdwReason=5 stands for? you can find it inside verifier.dll / AVrfpMiniLoadAttach call - lots of LdrQueryImageFileKeyOption checks
100
Hexacorn @hexacorn.bsky.social · 06/10/2025
ntprint.exe lolbin www.hexacorn.com/blog/2025/10...
062
Reposted by Hexacorn
sixtyvividtails @sixtyvividtails.bsky.social · 05/10/2025
Close your eyes and ✨imagine: From a low-integrity process (from LPAC even), you can inject your data anywhere you want: privileged tasks, PPL/protected processes, the OS kernel itself, and VTL1 trustlets. Now open your eyes. It is not hypothetical. It is the reality. Read it on page 33.
065
Hexacorn @hexacorn.bsky.social · 04/10/2025
Using .LNK files as lolbins www.hexacorn.com/blog/2025/10...
184
Hexacorn @hexacorn.bsky.social · 20/09/2025
RunDll Exporters www.hexacorn.com/blog/2025/09...
182
Hexacorn @hexacorn.bsky.social · 19/09/2025
Enter Sandbox 30: Static Analysis gone wrong www.hexacorn.com/blog/2025/09...
062
Hexacorn @hexacorn.bsky.social · 09/09/2025
Beyond good ol’ Run key, Part 151 www.hexacorn.com/blog/2025/09...
032
Hexacorn @hexacorn.bsky.social · 04/09/2025
DLL ForwardSideloading, Part 2 www.hexacorn.com/blog/2025/09...
192
Hexacorn @hexacorn.bsky.social · 19/08/2025
DLL ForwardSideloading www.hexacorn.com/blog/2025/08... using forwarded DLL functions for sideloading purposes
1115
Hexacorn @hexacorn.bsky.social · 17/08/2025
Beyond good ol’ Run key, Part 150 www.hexacorn.com/blog/2025/08...
172
Hexacorn @hexacorn.bsky.social · 14/08/2025
Life of a blogger
110
Reposted by Hexacorn
Volexity @volexity.com · 11/08/2025
@volexity.com has released updates to its #opensource GoResolver project and more! This work was part of a project for one of our #summerinternship students. Read more details about Volexity’s updated GoResolver projects + other #golang tools in our special blog post!
volexity.com
Go Get 'Em: Updates to Volexity Golang Tooling
Volexity’s GoResolver tool was released in April 2025 to help with analysis of these samples, reducing analyst load when working with obfuscated Golang binaries. However, there are still some difficul...
1910
Reposted by Hexacorn
Olaf Hartong @olafhartong.nl · 06/08/2025
During my #BHUSA talk I've released many ETW research tools, of which the most notable is BamboozlEDR. This tool allows you to inject events into ETW, allowing you to generate fake alerts and blind EDRs. github.com/olafhartong/... Slides available here: github.com/olafhartong/...
github.com
GitHub - olafhartong/BamboozlEDR: A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.
A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes. - olafhartong/BamboozlEDR
02515
Hexacorn @hexacorn.bsky.social · 14/07/2025
CVE-2005-4560 and Windows Macros + all exploit packs roll in their graves when they see ClickFix and FileFix...
020
Hexacorn @hexacorn.bsky.social · 12/07/2025
1 little known secret of advpack.dll, LaunchINFSection www.hexacorn.com/blog/2025/07...
020
Reposted by Hexacorn
malmoeb.bsky.social @malmoeb.bsky.social · 10/07/2025
1/ During a recent incident response case, we observed the following file access: \\localhost\C$\@ GMT-2025.06.21-10.53.43\Windows\NTDS\ntds.dit This is a clever method of accessing a Volume Shadow Copy (VSS) snapshot.
1125
Hexacorn @hexacorn.bsky.social · 06/07/2025
Beyond good ol’ Run key, Part 148 www.hexacorn.com/blog/2025/07...
051
Hexacorn @hexacorn.bsky.social · 06/07/2025
Beyond good ol’ Run key, Part 147 www.hexacorn.com/blog/2025/07...
041
Hexacorn @hexacorn.bsky.social · 29/06/2025
malmoeb.bsky.social is one of the best people to follow; in the era of generative AI it's easy to lose motivation for doing anything really, so his posts discussing so many interesting attacks is a breath of fresh air (and even if it is his AI posting it :-P, it's that very goo' ol' school vibe)
030
Hexacorn @hexacorn.bsky.social · 16/06/2025
clever carding page hxxps://gov[.]comsitebab[.]life/gov when you visit from the desktop, it's just a regular website (although compromised) when you visit from a smartphone, you get a fake gov web site that harvests your CC details
032
Reposted by Hexacorn
sixtyvividtails @sixtyvividtails.bsky.social · 15/06/2025
Did you know Windows has built-in RAM disk? And not just your regular RAM disk. It's pmem/nvdimm, via built-in scmbus.sys facility! That means you can make 🦆🦆🦆 #dax volume, so data/image mappings (section views) will use "drive" directly! No data persistence, no w10; only ws2022/w11+. EZ 📀 create:
Collage of screenshots showing how to enable emulated ramdisk and set its size via registry parameters for scmbus.sys.
Also shown: how to create partition and properly format the DAX volume.


1. Create ramdisk of 0x1234_MB:

cmd /v/c"set R=reg add HKLM\SYSTEM\CurrentControlSet\Services\scmbus /f /v&!R! CreateSimulatedRamdiskRootDevice /t 4 /d 1 &!R! RamdiskSizeInBytes /t 11 /d 0x123400000 &sc start scmbus"

(reboot required, unless you're lucky).


2. Create parition as usual:

list disk
select disk NNNN
convert gpt
create partition primary
assign letter X:


3. And format volume with DAX support:

format X: /fs:ntfs /Q /L /DAX
172
Hexacorn @hexacorn.bsky.social · 15/06/2025
VMwareResolutionSet.exe VMwareResolutionSet.dll lolbin www.hexacorn.com/blog/2025/06...
042
Hexacorn @hexacorn.bsky.social · 15/06/2025
wermgr.exe boot offdmpsvc.dll lolbin www.hexacorn.com/blog/2025/06... #lolbin
020
Hexacorn @hexacorn.bsky.social · 15/06/2025
wpr.exe boottrace phantom dll axeonoffhelper.dll lolbin www.hexacorn.com/blog/2025/06... #lolbin
020
Reposted by Hexacorn
Wietze @wietzebeukema.nl · 09/06/2025
#HuntingTipOfTheDay: Services can provide persistence. Looking for changes to their commands is common, but the lesser known Environment setting is often overlooked. It could result in stealthy DLL hijacking. Inspect any paths referenced for suspicious files.
232
Reposted by Hexacorn
hasherezade.bsky.social @hasherezade.bsky.social · 06/06/2025
New #TinyTracer (v3.0) is out - with many cool features: github.com/hasherezade/... - check them out!
1156
Reposted by Hexacorn
malmoeb.bsky.social @malmoeb.bsky.social · 05/06/2025
While investigating a compromised network, we found suspicious PowerShell code that ran on a domain controller. The script downloaded a file called chrome_installer.exe and installed it. We checked the file and found it was signed by Google, so it’s a genuine Chrome installer.
121
Hexacorn @hexacorn.bsky.social · 01/06/2025
mscoree.dll, RunDll32ShimW lolbin www.hexacorn.com/blog/2025/05...
073