Sign in

James Forshaw

@tiraniddo.dev
1.9K followers 185 following 131 posts

Security researcher in Google Project Zero. Author of Attacking Network Protocols. Posts are my own etc.

PostsRepliesMedia
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 21/09/2026
In July, Microsoft fixed CVE-2026-50343, a Windows privilege escalation bug reported by Calif and 9 others, dubbed “Dark Elevator”. But was it really fixed? projectzero.google/2026/09/wind...
projectzero.google
Windows Exploitation Techniques: Dangling COM Object Registrations
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in...
032
James Forshaw @tiraniddo.dev · 07/04/2026
I've put up the slides from my Zer0Con 2026 presentation on Administrator Protection. github.com/tyranid/info...
github.com
064
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 26/02/2026
In the final part of his blog series, @tiraniddo.dev tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process. projectzero.google/2026/02/gphf...
projectzero.google
A Deep Dive into the GetProcessHandleFromHwnd API - Project Zero
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass us...
064
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 12/02/2026
Part 2 of @tiraniddo.dev’s Windows Administrator Protection journey is here! projectzero.google/2026/02/wind...
projectzero.google
Bypassing Administrator Protection by Abusing UI Access - Project Zero
In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn’t exi...
165
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 26/01/2026
No security feature is perfect. @tiraniddo.dev reviewed Windows’ new Administrator Protection and found several bypasses. projectzero.google/2026/26/wind...
projectzero.google
Bypassing Windows Administrator Protection - Project Zero
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Cont...
065
Reposted by James Forshaw
Steve Syfuhs @syfuhs.net · 16/06/2025
Good Monday morning tech nerds. One of my devs wrote *another* blog post about kerberos (I'm creating an army of crazy bloggers). This one you might consider bookmarking.
techcommunity.microsoft.com
Introduction to Network Trace Analysis 06: Kerberos it’s AUTH-some! | Microsoft Community Hub
New to the series? Be sure to check out the previous posts!    Introduction to Network Trace Analysis Part 0: Laying the...
25121
Reposted by James Forshaw
RedTeam Pentesting @redteam-pentesting.de · 11/06/2025
🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live: 🪞The Reflective Kerberos Relay Attack - Remote privilege escalation from low-priv user to SYSTEM with RCE by applying a long forgotten NTLM relay technique to Kerberos: blog.redteam-pentesting.de/2025/reflect...
blog.redteam-pentesting.de
A Look in the Mirror - The Reflective Kerberos Relay Attack
It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While rese...
173
Reposted by James Forshaw
David (DWIZZZLE) Weston @dwizzzle.bsky.social · 19/05/2025
We are removing default admin in Windows 11, get your apps ready now blogs.windows.com/windowsdevel...
blogs.windows.com
Enhance your application security with administrator protection
Introduction Administrator protection is a new Windows 11 platform security feature that aims to protect the admin users on the device while still allowing them to perform the necessary functions whic...
23819
Reposted by James Forshaw
No Starch Press @nostarchpress.bsky.social · 08/05/2025
@tiraniddo.dev and Eugene Lim—authors of Windows Security Internals and From Day Zero to Zero Day—are at Off-By-One doing what they do best: giving keynotes and running a smart device hacking village, respectively. offbyone.sg
offbyone.sg
Off-by-One Conference 2025
Off-by-One Conference is a cybersecurity conference where like-minded professionals gather and exchange technical insights while gaining knowledge from one another. As the offensive security landscape...
041
James Forshaw @tiraniddo.dev · 29/04/2025
Maybe I’ll pop down to sf for rsa tomorrow. I’ve fortunately never gone before but this is my last chance and I really need a new ai security product.
060
Reposted by James Forshaw
Kevin Beaumont @doublepulsar.com · 21/04/2025
I took a look at the changes to Microsoft Recall, which is rolling out to compatible Windows devices soon. Photographic memory that stores all your deleted messages, keystrokes etc 😅 doublepulsar.com/microsoft-re...
doublepulsar.com
Microsoft Recall on Copilot+ PC: testing the security and privacy implications
A look at the risks and tradeoffs with Microsoft Recall.
69446
Reposted by James Forshaw
Andrea P @decoder-it.bsky.social · 14/03/2025
KrbRelayEx-RPC tool is out! 🎉 Intercepts ISystemActivator requests, extracts Kerberos AP-REQ & dynamic port bindings and relays the AP-REQ to access SMB shares or HTTP ADCS, all fully transparent to the victim ;) github.com/decoder-it/K...
github.com
GitHub - decoder-it/KrbRelayEx-RPC
Contribute to decoder-it/KrbRelayEx-RPC development by creating an account on GitHub.
0910
James Forshaw @tiraniddo.dev · 10/02/2025
I can now see why my email offering to give the NSA exclusive access to an ultra rare uber 1337 EoP in Windows NT 3.1 bounced 😭 Truly the dumbest timeline.
0121
Reposted by James Forshaw
Janel Comeau 🍁 @verybadllama.bsky.social · 02/02/2025
hey quick question does Goliath win in that story
1033330175272
James Forshaw @tiraniddo.dev · 30/01/2025
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...
googleprojectzero.blogspot.com
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
26541
Reposted by James Forshaw
Marc-André Moreau @awakecoding.com · 28/01/2025
My RDP IO Lab presentation on "Decrypting and Inspecting RDP traffic in Wireshark" was just *cancelled* - apparently Microsoft decided they would only do internal presentations, with no guest speakers 😠 What's the point of even trying when you get treated like this?
4195
James Forshaw @tiraniddo.dev · 28/01/2025
It's good to see some of the "authentication" vectors being patched in Admin Protection. I might look at it again once it's actually considered complete, don't want MS on my back again :D
041
Reposted by James Forshaw
Synacktiv @synacktiv.com · 27/01/2025
In our latest article, @croco_byte proposes an implementation of a trick discovered by James Forshaw in his research regarding Kerberos relaying. Discover how to perform pre-authenticated Kerberos relay over HTTP with our Responder and krbrelayx pull requests! www.synacktiv.com/publications...
synacktiv.com
Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx
01612
Reposted by James Forshaw
hasherezade.bsky.social @hasherezade.bsky.social · 26/01/2025
In case if you wonder what broke #ProcessHollowing on Windows 11 24H2, I have something for you: hshrzd.wordpress.com/2025/01/27/p...
hshrzd.wordpress.com
Process Hollowing on Windows 11 24H2
Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is us…
05838
Reposted by James Forshaw
EricLaw 🎻 @ericlawrence.com · 22/01/2025
Azure Trusted Signing is now available for individuals techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Trusted Signing is now open for individual developers to sign up in Public Preview! | Microsoft Community Hub
Exciting news for developers! Individual developers can now sign their apps with Trusted Signing. 
33110
Reposted by James Forshaw
Charlotte Garden @charlottegarden.bsky.social · 22/01/2025
An embarrassment of riches
1183309451
James Forshaw @tiraniddo.dev · 22/01/2025
You know you travel too much when you get top tier status on the three main airline alliances at the same time. Fortunately moving back to the UK will probably mean I’ll slow it down as I doubt I’ll travel much to the USA anymore.
180
Reposted by James Forshaw
WildByDesign @wildbydesign.bsky.social · 13/01/2025
It took me about a month, but I've got my win32-appcontainer-tools ready to share. - Launch Win32 apps in AppContainer - Set ACL permissions per-container - ETW tracing for Permissive Learning Mode Special thanks to Fredrik Orderud, @tiraniddo.dev and Helge Klein.
Set AppContainer ACLLaunch AppContainerAppContainer Permissive Learning Mode
1122
Reposted by James Forshaw
Jack @jackinpogform.bsky.social · 13/01/2025
Either Keir Starmer is the biggest mark to ever live or he's still hoping for a few 'freebies' from his corpo mates. I cannot understate how atrocious this is.
Politics
‘Mainlined into UK’s veins’: Labour announces huge public rollout of AI
Plans to make UK world leader in AI sector include opening access to NHS and other public dataTechnology companies including Microsoft, Anthropic and OpenAI welcomed the plan as Starmer said the “AI industry needs a government that is on their side”. Regulators will be told to “actively support innovation”, setting up a potential clash with people who believe regulators’ primary role should be to protect the public from harm.
1322461
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 07/01/2025
Project Zero is hiring 🎉 Please share with anyone you think would be great for the team www.google.com/about/career...
google.com
Senior Security Engineer, Security Research — Google Careers
01210
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 10/01/2025
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click project-zero.issues.chromium.org/issues/36869...
project-zero.issues.chromium.org
Project Zero
13816
Reposted by James Forshaw
Frank Lesniak @franklesniak.com · 05/01/2025
I've been dealing with mysterious high CPU utilization from WmiPrvSE.exe for MONTHS. I finally did some digging using github.com/luctalpe/WMI... (run wmimon from an elevated cmd prompt). Guess what the culprit was?
github.com
GitHub - luctalpe/WMIMon: Tool to monitor WMI activity on Windows
Tool to monitor WMI activity on Windows. Contribute to luctalpe/WMIMon development by creating an account on GitHub.
3308
Reposted by James Forshaw
echolevel @echolevel.co.uk · 04/01/2025
I added a true 14-bit MIDI mode to my controller and it's very smooth indeed. Ableton Live maps it with no issues and while I had to make a slight compromise on speed, the high resolution accuracy over a 100mm fader feels great. Boring details to follow. #gameaudio #gamedev #screenshotsaturday
1163
James Forshaw @tiraniddo.dev · 15/12/2024
Anyone who says UK food is terrible clearly doesn’t know about the greatest culinary invention yet conceived.
A picture of a pot of Bisto gravy granules that is Pigs In Blankets flavor which is a very common side dish at British Christmas dinners.
150
Reposted by James Forshaw
Jordan Borean @jborean.bsky.social · 13/12/2024
Ever wanted to know what data #PowerShell or other programs send to AMSI. I wrote a C# COM server implementation that logs this data as a JSON string. Had some fun learning more about COM and .NET AOT with this little project github.com/jborean93/Am...
13514
James Forshaw @tiraniddo.dev · 12/12/2024
A companion blog to my Bluehat 2024 presentation on OleView.NET is up now. googleprojectzero.blogspot.com/2024/12/wind...
googleprojectzero.blogspot.com
01812
James Forshaw @tiraniddo.dev · 12/12/2024
PSA, if you’re doing slides for a conference presentation always assume the bottom quarter of the slide can’t be seen so don’t put anything important there. This isn’t a criticism of this specific talk it’s a common issue. Some blame can be levied at the conference as well for the setup.
A photo of a slide from a talk being presented live at Blackhat Europe 2024. There’s an important block of text at the bottom of the slide buts it’s unreadable from the photographers view point because other peoples heads are blocking it.
0181
James Forshaw @tiraniddo.dev · 09/12/2024
I'm going to be at Blackhat Europe 2024 this Wednesday and Thursday. I should also be at BSides London. Just in case anyone wants to find me to sign a book or complain about something Windows related :D
182
James Forshaw @tiraniddo.dev · 08/12/2024
Lol, found a new PPL injection technique which works on Win11 24H2 (admittedly needs admin, but not that bothered about that). I'll try and blog about it at some point :)
2290
Reposted by James Forshaw
D̒͂̕ᵈăᵃn̕ᶰ Ť̾̾̓͐͒͠ᵗe͗̑́̋̂́͡ᵉn̅ᶰtᵗl̀̓͘ᶫe̓̒̂̚ᵉrʳ @viss.hax.lol · 01/12/2024
for anyone out there who wants to download vmware "now that its free", but doesnt want to go through the fucking cirque de soleil trapeze act of auth and redirects and entitlements, someone on masto linked me to this - where you can just fetch ... everything, without need for their bullshit!
softwareupdate.vmware.com
CDS Repository - /var/www/public/stage/session-120/cds/vmw-desktop
65613
James Forshaw @tiraniddo.dev · 01/12/2024
@remkoweijnen.bsky.social I've stopped interacting with the bad site now, but I did notice you asked about a signed copy of my book. I might be able to get you one, depending on logistics :)
250
Reposted by James Forshaw
Andrea P @decoder-it.bsky.social · 25/11/2024
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/K...
36343
Reposted by James Forshaw
EricLaw 🎻 @ericlawrence.com · 25/11/2024
First draft is out Fiddler - Mistakes and Happy Accidents textslashplain.com/2024/11/24/f...
textslashplain.com
Fiddler – My Mistakes
On a flight back from Redmond last week, I finally read Linus Torvalds’ 2002 memoir “Just For Fun.” I really enjoyed its picture of Linux (and Torvalds) early in its success, with…
126525
James Forshaw @tiraniddo.dev · 25/11/2024
Awesome that MS are supported and documenting VBS enclaves properly. learn.microsoft.com/en-us/window.... Also awesome that in the example exported entry point they provide they don't seem to mention how careful you need to be with the input pointer that you don't just read/write enclave memory :)
learn.microsoft.com
VBS Enclaves Development Guide - Secure Enclaves
Development guide for Virtualization-based security (VBS) enclaves - Learn how to build a basic VBS enclave.
1155
Reposted by James Forshaw
2DArray @2darray.bsky.social · 23/11/2024
#pico8 ?"\^!5f101😐<😐1🐱2🅾️◆?7♥웃8☉2" ::_::u=rnd(128)v=rnd(128)g=u-99h=v-64d=max(20,sqrt(g*g+h*h))c=9+d/20+rnd() if(v>65)p=v-64z=120/(v-64)x=(u-64)/p d=sqrt(x*x+z*z)s=z/d+x/d/4w=(z+sin(x/3+t()/8)+rnd())%4c=w+(c-w)*min(z/40+s^14/4,1) pset(u,v,c)goto _
616625
Reposted by James Forshaw
Andrea P @decoder-it.bsky.social · 20/11/2024
Following my prev tweet, my Kerberos MITM relay/forwarder is almost finished! It targets for example insecure DNS updates in AD, allowing DNS name forgery. It intercepts, relays, and forwards traffic, with the client unaware. Currently supporting smb->smb and smb->http (adcs)
13614
Reposted by James Forshaw
nodauf.bsky.social @nodauf.bsky.social · 20/11/2024
Interesting blog post from Synacktiv on relaying kerberos over smb (based on the work of @decoder-it.bsky.social and @tiraniddo.bsky.social ) www.synacktiv.com/publications...
synacktiv.com
Relaying Kerberos over SMB using krbrelayx
062
Reposted by James Forshaw
Paged Out! @pagedout.bsky.social · 19/11/2024
Paged Out! Issue #5 is out now! pagedout.institute?page=issues.... Happy reading!
05833
Reposted by James Forshaw
Nick Gonzo @nickgonzo.bsky.social · 19/11/2024
The past really is a different country.
011
James Forshaw @tiraniddo.dev · 16/11/2024
A picture of Mount Fuji at sunset
020
James Forshaw @tiraniddo.dev · 15/11/2024
Thanks LinkedIn, maybe you’re another service I don’t need.
Linked in email subject recommending I follow Vivek Ramaswamy. Yeah no I’m good.
172
James Forshaw @tiraniddo.dev · 13/11/2024
My latest OleView.NET calls proxy methods by generating a NDR marshaling class and calling the underlying IRpcChannelBuffer. This doesn't work if the interface is in process as there's no RPC channel. I _just_ realized I have the stub instance so I can join to two to call in-process methods 🤦‍♂️
030
Reposted by James Forshaw
Barry Dorrans @blowdart.me · 13/11/2024
🍻
learn.microsoft.com
Breaking change: In-box BinaryFormatter implementation removed and always throws - .NET
Learn about the .NET 9 breaking change in serialization where the in-box BinaryFormatter implementation was removed and always throws exceptions.
7287
James Forshaw @tiraniddo.dev · 12/11/2024
Remembering my first BHUSA presentation makes me slightly sad that Context IS is no longer around as a company. Now I've got a little time on my hands with not being at work, perhaps it's time to bring CANAPE (github.com/tyranid/canape) that I wrote there into the modern age and port it to .NET 9 :)
github.com
GitHub - tyranid/canape: CANAPE Network Testing Tool
CANAPE Network Testing Tool. Contribute to tyranid/canape development by creating an account on GitHub.
271