Sign in

James Forshaw

@tiraniddo.dev
1.9K followers 185 following 131 posts

Security researcher in Google Project Zero. Author of Attacking Network Protocols. Posts are my own etc.

PostsRepliesMedia
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 21/09/2026
In July, Microsoft fixed CVE-2026-50343, a Windows privilege escalation bug reported by Calif and 9 others, dubbed “Dark Elevator”. But was it really fixed? projectzero.google/2026/09/wind...
projectzero.google
Windows Exploitation Techniques: Dangling COM Object Registrations
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in...
032
James Forshaw @tiraniddo.dev · 07/04/2026
I've put up the slides from my Zer0Con 2026 presentation on Administrator Protection. github.com/tyranid/info...
github.com
064
James Forshaw @tiraniddo.dev · 07/04/2026
Damn, that was a while ago :)
000
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 26/02/2026
In the final part of his blog series, @tiraniddo.dev tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process. projectzero.google/2026/02/gphf...
projectzero.google
A Deep Dive into the GetProcessHandleFromHwnd API - Project Zero
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass us...
064
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 12/02/2026
Part 2 of @tiraniddo.dev’s Windows Administrator Protection journey is here! projectzero.google/2026/02/wind...
projectzero.google
Bypassing Administrator Protection by Abusing UI Access - Project Zero
In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn’t exi...
165
Reposted by James Forshaw
Natalie Silvanovich @natashenka.bsky.social · 26/01/2026
No security feature is perfect. @tiraniddo.dev reviewed Windows’ new Administrator Protection and found several bypasses. projectzero.google/2026/26/wind...
projectzero.google
Bypassing Windows Administrator Protection - Project Zero
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Cont...
065
James Forshaw @tiraniddo.dev · 21/07/2025
I guess there’s something about Superman movies. Man of steel is one of the only movies I’ve ever walked out of. And that was with my wife so didn’t even need the solo advantage it was just that bad. Wasn’t planning on seeing the new one tbh.
010
James Forshaw @tiraniddo.dev · 02/07/2025
Now if only you’d stop trying to make it out of date 😄 then again that’s what second editions are for.
160
Reposted by James Forshaw
Steve Syfuhs @syfuhs.net · 16/06/2025
Good Monday morning tech nerds. One of my devs wrote *another* blog post about kerberos (I'm creating an army of crazy bloggers). This one you might consider bookmarking.
techcommunity.microsoft.com
Introduction to Network Trace Analysis 06: Kerberos it’s AUTH-some! | Microsoft Community Hub
New to the series? Be sure to check out the previous posts!    Introduction to Network Trace Analysis Part 0: Laying the...
25121
Reposted by James Forshaw
RedTeam Pentesting @redteam-pentesting.de · 11/06/2025
🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live: 🪞The Reflective Kerberos Relay Attack - Remote privilege escalation from low-priv user to SYSTEM with RCE by applying a long forgotten NTLM relay technique to Kerberos: blog.redteam-pentesting.de/2025/reflect...
blog.redteam-pentesting.de
A Look in the Mirror - The Reflective Kerberos Relay Attack
It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While rese...
173
James Forshaw @tiraniddo.dev · 22/05/2025
Sure but maybe it shouldn’t be remembering them wholesale in the first place?
120
James Forshaw @tiraniddo.dev · 21/05/2025
I despair that in the UK you now need ID to buy a cutlery set with normal non-sharp table knives. And if they ban sharp points on kitchen knives I assume they’ll ban metal files so you can’t grind a new point on them. I just don’t see how it really helps other than pandering to the tabloids.
100
Reposted by James Forshaw
David (DWIZZZLE) Weston @dwizzzle.bsky.social · 19/05/2025
We are removing default admin in Windows 11, get your apps ready now blogs.windows.com/windowsdevel...
blogs.windows.com
Enhance your application security with administrator protection
Introduction Administrator protection is a new Windows 11 platform security feature that aims to protect the admin users on the device while still allowing them to perform the necessary functions whic...
23819
James Forshaw @tiraniddo.dev · 14/05/2025
The distinction without a difference.
030
Reposted by James Forshaw
No Starch Press @nostarchpress.bsky.social · 08/05/2025
@tiraniddo.dev and Eugene Lim—authors of Windows Security Internals and From Day Zero to Zero Day—are at Off-By-One doing what they do best: giving keynotes and running a smart device hacking village, respectively. offbyone.sg
offbyone.sg
Off-by-One Conference 2025
Off-by-One Conference is a cybersecurity conference where like-minded professionals gather and exchange technical insights while gaining knowledge from one another. As the offensive security landscape...
041
James Forshaw @tiraniddo.dev · 29/04/2025
Maybe I’ll pop down to sf for rsa tomorrow. I’ve fortunately never gone before but this is my last chance and I really need a new ai security product.
060
James Forshaw @tiraniddo.dev · 25/04/2025
I apologize for the void moaning back 😄
030
James Forshaw @tiraniddo.dev · 25/04/2025
To be fair they are specialisms not everyone can be both. I’ve know quite a few people who are the exact opposite.
110
James Forshaw @tiraniddo.dev · 22/04/2025
Even funnier that’s it’s Kneecap. What does she think their name references?
010
Reposted by James Forshaw
Kevin Beaumont @doublepulsar.com · 21/04/2025
I took a look at the changes to Microsoft Recall, which is rolling out to compatible Windows devices soon. Photographic memory that stores all your deleted messages, keystrokes etc 😅 doublepulsar.com/microsoft-re...
doublepulsar.com
Microsoft Recall on Copilot+ PC: testing the security and privacy implications
A look at the risks and tradeoffs with Microsoft Recall.
69446
James Forshaw @tiraniddo.dev · 21/04/2025
You mean the iPhone with signal on it?
040
James Forshaw @tiraniddo.dev · 03/04/2025
When they were talking about the UK-US trade deal that could be struck after brexit they really meant only 10% tariffs instead of 20%
241
Reposted by James Forshaw
Andrea P @decoder-it.bsky.social · 14/03/2025
KrbRelayEx-RPC tool is out! 🎉 Intercepts ISystemActivator requests, extracts Kerberos AP-REQ & dynamic port bindings and relays the AP-REQ to access SMB shares or HTTP ADCS, all fully transparent to the victim ;) github.com/decoder-it/K...
github.com
GitHub - decoder-it/KrbRelayEx-RPC
Contribute to decoder-it/KrbRelayEx-RPC development by creating an account on GitHub.
0910
James Forshaw @tiraniddo.dev · 27/02/2025
Good. When Microsoft actually play fair in this I’m sure it’ll be welcomed. A blog post about future plans isn’t a substitute.
100
James Forshaw @tiraniddo.dev · 20/02/2025
And that photo really seals it, "Hi poors, how are you? *aside to aide* They can't jump the fence can they?"
010
James Forshaw @tiraniddo.dev · 18/02/2025
Invoke EU right to be forgotten?
010
James Forshaw @tiraniddo.dev · 14/02/2025
Tbh the real cowardice is not changing it outright for all English locales and instead putting it in parentheses. They’re already angering people with their dumb decision I doubt they could make it worse by clearly throwing in the towel.
010
James Forshaw @tiraniddo.dev · 14/02/2025
What does Bing call it? Oh wait no one cares.
100
James Forshaw @tiraniddo.dev · 11/02/2025
TBH googleprojectzero.blogspot.com/2021/08/unde... is probably more comprehensive.
googleprojectzero.blogspot.com
Understanding Network Access in Windows AppContainers
Posted by James Forshaw, Project Zero Recently I've  been delving into the inner workings of the Windows Firewall. This is interesting to ...
031
James Forshaw @tiraniddo.dev · 10/02/2025
I can now see why my email offering to give the NSA exclusive access to an ultra rare uber 1337 EoP in Windows NT 3.1 bounced 😭 Truly the dumbest timeline.
0121
James Forshaw @tiraniddo.dev · 03/02/2025
When physical risks are "There's more guns than people" I could perhaps see some hesitancy. Though, there are people like AOC pushing back. However, most are too set in their ways and too beholden to their benefactors that they don't want to rock the boat. It might even be good for them.
120
James Forshaw @tiraniddo.dev · 03/02/2025
Are you really upper middle class if you’re doing your own shopping? 😄
030
Reposted by James Forshaw
Janel Comeau 🍁 @verybadllama.bsky.social · 02/02/2025
hey quick question does Goliath win in that story
1033330175272
James Forshaw @tiraniddo.dev · 02/02/2025
Funnily the de minimis exception was something I was going to miss going back to the uk. I guess it doesn’t matter now 😂
120
James Forshaw @tiraniddo.dev · 02/02/2025
I wonder how it impacts bonded warehouses? Presumably the base tariff would increase. I ordered some parts from digikey recently and the tariff cost was an explicit line item on the invoice.
110
James Forshaw @tiraniddo.dev · 02/02/2025
Glad I did a aliexpress blitz in December 😄
110
James Forshaw @tiraniddo.dev · 31/01/2025
I did take a look and couldn't find it. It ultimately ends up in the SMB client driver who processes it, the MUP redirector doesn't look at it.
010
James Forshaw @tiraniddo.dev · 30/01/2025
New blog post on the abuse of the IDispatch COM interface to get unexpected objects loaded into a process. Demoed by using this to get arbitrary code execution in a PPL process. googleprojectzero.blogspot.com/2025/01/wind...
googleprojectzero.blogspot.com
Windows Bug Class: Accessing Trapped COM Objects with IDispatch
Posted by James Forshaw, Google Project Zero Object orientated remoting technologies such as DCOM and .NET Remoting make it very easy ...
26541
Reposted by James Forshaw
Marc-André Moreau @awakecoding.com · 28/01/2025
My RDP IO Lab presentation on "Decrypting and Inspecting RDP traffic in Wireshark" was just *cancelled* - apparently Microsoft decided they would only do internal presentations, with no guest speakers 😠 What's the point of even trying when you get treated like this?
4195
James Forshaw @tiraniddo.dev · 28/01/2025
It's good to see some of the "authentication" vectors being patched in Admin Protection. I might look at it again once it's actually considered complete, don't want MS on my back again :D
041
James Forshaw @tiraniddo.dev · 28/01/2025
I asked an expert (my 10 month old) and from "Gurgle blah blah blah" I assume they meant, "Time is an illusion, lunchtime doubly so. Speaking of which where's my dinner?". I might be mistranslating.
131
Reposted by James Forshaw
Synacktiv @synacktiv.com · 27/01/2025
In our latest article, @croco_byte proposes an implementation of a trick discovered by James Forshaw in his research regarding Kerberos relaying. Discover how to perform pre-authenticated Kerberos relay over HTTP with our Responder and krbrelayx pull requests! www.synacktiv.com/publications...
synacktiv.com
Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx
01612
Reposted by James Forshaw
hasherezade.bsky.social @hasherezade.bsky.social · 26/01/2025
In case if you wonder what broke #ProcessHollowing on Windows 11 24H2, I have something for you: hshrzd.wordpress.com/2025/01/27/p...
hshrzd.wordpress.com
Process Hollowing on Windows 11 24H2
Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is us…
05838
Reposted by James Forshaw
EricLaw 🎻 @ericlawrence.com · 22/01/2025
Azure Trusted Signing is now available for individuals techcommunity.microsoft.com/blog/microso...
techcommunity.microsoft.com
Trusted Signing is now open for individual developers to sign up in Public Preview! | Microsoft Community Hub
Exciting news for developers! Individual developers can now sign their apps with Trusted Signing. 
33110
James Forshaw @tiraniddo.dev · 22/01/2025
I do appreciate them making this available but how many individuals are going to need 5000 signatures a month? I might be interested if there was a hobbyist tier with maybe 100 signatures for much less. That said it still seems cheaper than paying for a real code signing cert even at $10/m.
110
James Forshaw @tiraniddo.dev · 22/01/2025
Sure, but having not lived in a little town in the sticks would you even get the VC funded ones? I'd have thought you're not just reliant on willing punters in those areas, but people willing to work for those wages?
100
James Forshaw @tiraniddo.dev · 22/01/2025
Brexit is a symptom of the electorate's stupidity not a cause. The British political class love paternalistic laws like these as they look good in the right wing press. Ironically this same press then complain about "nanny state" laws when it directly affects their demographic.
020
James Forshaw @tiraniddo.dev · 22/01/2025
Maybe next week, as long as there's no requested edits. If there are, as I'm not at work, it might be trickier :)
020
James Forshaw @tiraniddo.dev · 22/01/2025
Pretty sure it was sustainable when each company did it themselves, it's only because we've add layers of grift to the process that it becomes expensive/exploitative (not saying the pizza delivery person wasn't being exploited)
200
James Forshaw @tiraniddo.dev · 22/01/2025
It's certainly possible, Labour are unashamedly swayed by the tech lobbyists. But then again it's probably just the usual doing something to stave off the Daily Fail.
020