Sign in

Sam Thomas

@xorpse.ghost.sh
141 followers 151 following 12 posts

Program Analysis / Reverse Engineering Website: xv.ax

PostsRepliesMedia
Sam Thomas @xorpse.ghost.sh · 26/07/2026
I'm pleased to announce a new release of the #idalib #Rust bindings for @hex-rays.bsky.social IDA Pro! This release adds compatibility with latest SDK, and a couple of bug fixes. Thanks to @raptor.infosec.exchange.ap.brid.gy and @yeggor.bsky.social for their contributions. github.com/idalib-rs/id...
github.com
GitHub - idalib-rs/idalib: Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib
Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib - idalib-rs/idalib
031
Sam Thomas @xorpse.ghost.sh · 07/03/2026
We @binarly.bsky.social just open-sourced our VulHunt framework at RE//verse! GitHub: github.com/vulhunt-re/v... Documentation: vulhunt.re/docs Slack: join.slack.com/t/vulhunt/sh... vulhunt.re
vulhunt.re
VulHunt
Vulnerability Detection Framework by Binarly's REsearch Team
1136
Sam Thomas @xorpse.ghost.sh · 20/02/2026
I'm pleased to announce a new release of the Rust bindings for @hex-rays.bsky.social IDA SDK! This release includes v9.3 compatibility. Code: git.idalib.rs Docs: docs.idalib.rs Thank you to @yeggor.bsky.social who contributed to this release, and to @hex-rays.bsky.social for their support.
git.idalib.rs
GitHub - idalib-rs/idalib: Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib
Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib - idalib-rs/idalib
020
Reposted by Sam Thomas
Quarkslab @quarkslab.bsky.social · 20/01/2026
We conducted the first public third-party security assessment of EVerest, an open-source firmware stack for electric vehicle charging stations, deployed in hundreds of thousands of charging points worldwide. The audit was mandated by @ostifofficial.bsky.social 🙏 blog.quarkslab.com/everest-secu...
022
Reposted by Sam Thomas
blacktop.bsky.social @blacktop.bsky.social · 17/01/2026
Created a single binary headless IDA MCP server in Rust using the awesome idalib by @binarly.bsky.social 🦀👩‍🔬 It adds tool discovery to not pollute your context (before @claudeai fixed it on their side 😏) github.com/blacktop/ida...
github.com
GitHub - blacktop/ida-mcp-rs: Headless IDA MCP Server
Headless IDA MCP Server. Contribute to blacktop/ida-mcp-rs development by creating an account on GitHub.
032
Reposted by Sam Thomas
blacktop.bsky.social @blacktop.bsky.social · 17/01/2026
Rust bindings for Apple's on-device LLM just dropped 🦀🍎 fm-rs lets you use Apple Intelligence from Rust - streaming, tool calling, structured output, all running locally github.com/blacktop/fm-rs
021
Reposted by Sam Thomas
Edward J. Schwartz @ejschwar.bsky.social · 15/01/2026
🚨 Blog Post: ""Idioms: A Simple and Effective Framework for Turbo-Charging Local Neural Decompilation with Well-Define... edmcman.github.io/blog/2026-01-15--…
011
Reposted by Sam Thomas
Hex-Rays @hex-rays.bsky.social · 05/11/2025
🔄In case you missed it... IDA Domain API. This new open-source Python API is designed to make scripting in IDA simpler, more consistent, and more natural. Check out the key features, code examples, documentation and more: ida-domain.docs.hex-rays.com
042
Reposted by Sam Thomas
Kristopher Micinski @krismicinski.bsky.social · 28/10/2025
Talk Tomorrow: "Scalable Static Analysis and High-Performance Logic Programming" (github.com/kmicinski/mi...)
github.com
1177
Reposted by Sam Thomas
Hex-Rays @hex-rays.bsky.social · 23/10/2025
📢 The Hex-Rays IDA Plugin Contest is open! We've updated the submission process, added more prizes, and IDA Free users can now enter to win. 📅 Submissions close: January 15, 2026 Get the full update here: hex-rays.com/plugin-contest Good luck!
032
Reposted by Sam Thomas
Lesly-Ann Daniel @lesly-ann.bsky.social · 22/09/2025
🚨 EURECOM is recruiting a PhD student (and master-level interns) on verification and testing at the hardware-software boundary 🌄 Amazing location between sea & mountain 💡 3-year position 🌍 International environment (no French required!) You're a curious and motivated student? Reach out!
064
Reposted by Sam Thomas
Romain Thomas (@rh0main) @rh0main.bsky.social · 15/09/2025
I'm happy to share that LIEF 0.17.0 is out: lief.re/blog/2025-09...
0145
Sam Thomas @xorpse.ghost.sh · 13/09/2025
I'm pleased to announce a new release of the Rust bindings for @hex-rays.bsky.social IDA SDK! This release includes v9.2 compatibility, and a number of new features and fixes. Code: git.idalib.rs Thank you to our contributors: @withzombies.bsky.social Cole Leavitt Irate-Walrus @yeggor.bsky.social
git.idalib.rs
GitHub - binarly-io/idalib: Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib
Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib - binarly-io/idalib
011
Reposted by Sam Thomas
Edward J. Schwartz @ejschwar.bsky.social · 11/09/2025
This looks like a cool way to declaratively orchestrate data processing: snakemake.github.io How haven't I heard of this before?
snakemake.github.io
Snakemake
011
Reposted by Sam Thomas
Mathy Vanhoef @vanhoefm.bsky.social · 13/08/2025
At USENIX Security? Then check out: Studying the Use of CVEs in Academia, won distinguished paper award www.usenix.org/conference/u... Discovering and Exploiting Vulnerable Tunnelling Hosts, won most innovative research Pwnie @ DEFCON www.usenix.org/conference/u... Big thanks to all co-authors!!
0157
Reposted by Sam Thomas
ic3qu33n @ic3qu33n.bsky.social · 26/07/2025
seeing my @vxundergroundre.bsky.social Black Mass article “EFI Byte Code Virtual Machine - A Monster Emerges” in the print copy of vol III at long last has me verklempt. All the blood,sweat+tears that I poured into writing the first UEFI EBC virus were v worth it. 🖤
vx-underground Black Mass Volume III zine print edition, coverArticle “EFI Byte Code Virtual Machine, A Monster Emerges” in vx-underground Black Mass Volume III zine print edition
162
Reposted by Sam Thomas
raptor @raptor.infosec.exchange.ap.brid.gy · 15/07/2025
Today I’m celebrating one year of #Rust! 🦀 I started learning it last summer, and since then, I’ve pretty much stopped programming in any other language. Over the past year, I’ve gone from playing with the basics to building some (hopefully 😜) useful […] [Original post on infosec.exchange]
My GitHub contribution graph for the past year
033
Sam Thomas @xorpse.ghost.sh · 15/07/2025
I'm pleased to announce a new version of the Rust bindings for IDA Pro! With: - Improved strings, metadata, and core APIs. - Support for the names API. Thank you to @raptor.infosec.exchange.ap.brid.gy & Willi Ballenthin for contributing! Docs: idalib.rs Code: git.idalib.rs
idalib.rs
idalib documentation
097
Reposted by Sam Thomas
Mathy Vanhoef @vanhoefm.bsky.social · 12/07/2025
Our research on open tunneling servers got nominated for the Most Innovative Research award :) The work will be presented by Angelos Beitis at Black Hat and also at USENIX Security Brief summary and code: github.com/vanhoefm/tun... Paper: papers.mathyvanhoef.com/usenix2025-t...
076
Reposted by Sam Thomas
Adrian Herrera @adrianherrera.bsky.social · 09/07/2025
CTADL - a Datalog-based interprocedural static taint analysis engine for Java/Android bytecode (via JADX) and Pcode (via Ghidra) Code: github.com/sandialabs/c... Talk (via @krismicinski.bsky.social): youtu.be/3ec9VfMUVa8?...
github.com
GitHub - sandialabs/ctadl: CTADL is a static taint analysis tool
CTADL is a static taint analysis tool. Contribute to sandialabs/ctadl development by creating an account on GitHub.
1122
Reposted by Sam Thomas
Kristopher Micinski @krismicinski.bsky.social · 07/07/2025
May 25-27, 2025, I hosted an event, the "Minnowbrook Logic Programming Seminar," in Blue Mountain Lake, NY. I recorded 11 talks on Datalog-related interests, totaling over 9+ hours of video, which I have just now published on YouTube youtu.be/3ec9VfMUVa8
youtu.be
Minnowbrook Logic Programming Seminar (Supercut w/ Extras)
YouTube video by Kristopher Micinski
2185
Reposted by Sam Thomas
HN Security @hnsec.infosec.exchange.ap.brid.gy · 18/06/2025
Exploring fault injection on ESP32 V3! Inspired by Delvaux work, we tested voltage #glitching as an attack vector. With advanced triggers & GDB, we achieved a ~1.5% success rate. #Hardware #FaultInjection is becoming more practical! […]
infosec.exchange
Original post on infosec.exchange
013
Reposted by Sam Thomas
Edward J. Schwartz @ejschwar.bsky.social · 16/06/2025
🚨 Blog Post: ""A Human Study of Automatically Generated Decompiler Annotations" Published at DSN 2025" edmcman.github.io/blog/2025-06-16--…
031
Reposted by Sam Thomas
Amnesty International UK @amnestyuk.bsky.social · 12/06/2025
ONLY 5 DAYS LEFT 🚨 The Crime and Policing Bill is in the House of Commons on Tuesday 17.06. We have 5 days left to email MPs to act. MPs right now have the power to protect our protest rights. We can’t let them ignore us. 📝 Take action: www.amnesty.org.uk/actions/emai...
placard saying protesting is our human right, with split image showing Westminister in the background
02520
Reposted by Sam Thomas
raptor @raptor.infosec.exchange.ap.brid.gy · 11/06/2025
Another Crack in the Chain of Trust: Uncovering (Yet Another) #SecureBoot Bypass www.binarly.io/blog/another-crack-i…
binarly.io
Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass
Comments
023
Reposted by Sam Thomas
raptor @raptor.infosec.exchange.ap.brid.gy · 11/06/2025
#Hydroph0bia (CVE-2025-4275) - a trivial #SecureBoot bypass for UEFI-compatible firmware based on Insyde #H2O, part 1 coderush.me/hydroph0bia-part1
coderush.me
Hydroph0bia (CVE-2025-4275) - a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O, part 1
015
Reposted by Sam Thomas
nora @noratrieb.dev · 09/06/2025
New blog post: noratrieb.dev/blog/posts/e...
noratrieb.dev
ELF Linking and Symbol Resolution
A summary on how linkers resolve symbols on Unix-like platforms
0334
Reposted by Sam Thomas
raptor @raptor.infosec.exchange.ap.brid.gy · 05/06/2025
My greatest achievement so far in the #rust ecosystem: the “security” category in crates.io is gaining traction 😉 crates.io/search?q=category%3Asecur…
022
Reposted by Sam Thomas
Romain Thomas (@rh0main) @rh0main.bsky.social · 27/05/2025
[Blog Post] New high-level API in LIEF that allows the creation of DWARF files. Additionally, I present two plugins designed to export program information from Ghidra and BinaryNinja into a DWARF file. lief.re/blog/2025-05... (Bonus: DWARF file detailing my reverse engineering work on DroidGuard)
lief.re
DWARF as a Shared Reverse Engineering Format
This blog post introduces a new API in LIEF to create DWARF files
12215
Reposted by Sam Thomas
Mathy Vanhoef @vanhoefm.bsky.social · 25/05/2025
All papers should publish their code. Help realize this by becoming an artifact reviewer at NDSS'26, apply here: docs.google.com/forms/d/e/1F... You'll review artifacts of accepted papers. We especially encourage junior/senior PhD students & PostDocs to help. Distinguished reviews will get awards!
docs.google.com
Self-nomination for the Artifact Evaluation Committee of NDSS 2026
We are looking for members of the Artifact Evaluation Committee (AEC) of NDSS 2026. The Network and Distributed System Security symposium adopts an Artifact Evaluation (AE) process allowing authors t...
01210
Sam Thomas @xorpse.ghost.sh · 21/05/2025
We're are happy to announce a new release of our #Rust bindings for idalib. What's new: - New APIs for working with IDBs, segments, and more - Rust 2024 support - New homepage: idalib.rs H/T to our contributors @yeggor.bsky.social & @raptor.infosec.exchange.ap.brid.gy github.com/binarly-io/i...
github.com
GitHub - binarly-io/idalib: Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib
Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.x’s idalib - binarly-io/idalib
059
Reposted by Sam Thomas
Edward J. Schwartz @ejschwar.bsky.social · 03/05/2025
🚨 Blog Post: "Re-compiling Decompiler Output" edmcman.github.io/blog/2025-05-02--…
012
Reposted by Sam Thomas
Philip Zucker @sandmouth.bsky.social · 28/04/2025
[New Blog Post] Proof Objects I Have Loved www.philipzucker.com/proof_objects/
philipzucker.com
Proof Objects I Have Loved
That proofs are things is a cool meta awareness that is one of the payoffs of studying mathematical logic.
141
Reposted by Sam Thomas
ic3qu33n @ic3qu33n.bsky.social · 31/03/2025
v happy to finally share my slides for my @reconmtl.bsky.social 2024 talk “GOP Complex: Image parsing bugs, EBC polymorphic engines and the Deus ex machina of UEFI exploit dev.” Really proud of this talk + v grateful to the amazing REcon team for another incredible con 🖤 github.com/ic3qu33n/REc...
github.com
GitHub - ic3qu33n/REcon2024-GOP-Complex: REcon 2024 Repo, slides for talk "GOP Complex: Image parsing bugs, EBC polymorphic engines and the Deus ex machina of UEFI exploit dev""
REcon 2024 Repo, slides for talk "GOP Complex: Image parsing bugs, EBC polymorphic engines and the Deus ex machina of UEFI exploit dev"" - ic3qu33n/REcon2024-GOP-Complex
0148
Reposted by Sam Thomas
raptor @raptor.infosec.exchange.ap.brid.gy · 28/03/2025
My first official rust-lang contribution 😜 github.com/rust-lang/crates.io/pull… On crates.io, you can now categorize your crate under “security” (“Crates related to cybersecurity, penetration testing, code review, vulnerability research, and reverse engineering.”) […]
infosec.exchange
Original post on infosec.exchange
041
Reposted by Sam Thomas
raptor @raptor.infosec.exchange.ap.brid.gy · 27/03/2025
My idalib-based "vulnerability divination" tool suite is finally available in the official Hex-Rays Plugins & Apps repository! 🦀 plugins.hex-rays.com/search-results… #idapro #idalib #vulnerabilityresearch #reverseengineering
plugins.hex-rays.com
Hex-Rays - Plugins & Apps
Your description here
011
Reposted by Sam Thomas
Edward J. Schwartz @ejschwar.bsky.social · 21/03/2025
The difference between the paper and reality.
131
Reposted by Sam Thomas
raptor @raptor.infosec.exchange.ap.brid.gy · 03/03/2025
I've just pushed to crates.io updated releases of my #VulnerabilityResearch tools written in #Rust, compatible with Hex-Rays IDA Pro 9.1 and upgraded to the Rust 2024 Edition. Thanks to @xorpse and Yegor Vasilenko at @binarly_io for the immediate update of their idalib Rust bindings! For more […]
infosec.exchange
Original post on infosec.exchange
033
Sam Thomas @xorpse.ghost.sh · 28/02/2025
We @binarly.bsky.social are pleased to announce a new release of our Rust bindings for Hex-Rays IDA Pro (crates.io/crates/idalib) with support for the latest v9.1 release! Special thanks to @yeggor.bsky.social for taking care of the changes needed to make everything compatible with this release!
crates.io
crates.io: Rust Package Registry
072
Reposted by Sam Thomas
Guillaume Hiet @guillaumehiet.bsky.social · 05/02/2025
We’re Hiring – Tenured Faculty Positions in Cybersecurity! CentraleSupélec is recruiting 2 tenured Ass. Prof. / Prof. in Cybersecurity at IRISA (UMR CNRS 6074), Rennes, France. Application deadline: April 14, 2025 Full job details: team.inria.fr/sushi/files/... Contact us before applying!
team.inria.fr
002
Reposted by Sam Thomas
ESET Research @esetresearch.bsky.social · 16/01/2025
#ESETresearch discovered and reported to #certcc a vulnerability that allows bypassing UEFI Secure Boot on most UEFI-based systems. This vulnerability, #CVE-2024-7344, was found by x.com/smolar_m in a UEFI app signed by Microsoft’s 3rd-party UEFI certificate. welivesecurity.com/en/eset-rese... 🧵1/4
welivesecurity.com
Under the cloak of UEFI Secure Boot: Introducing CVE-2024-7344
ESET researchers have discovered a vulnerability that affects the majority of UEFI-based systems and allows bypassing UEFI Secure Boot.
11210
Reposted by Sam Thomas
HN Security @hnsec.infosec.exchange.ap.brid.gy · 15/01/2025
In this new @hnsec blog post, @MrAle_98@twitter.com demonstrates how to leverage the I/O Ring technique to bypass the latest #exploit mitigations, such as hypervisor-protected code integrity (#HVCI), and achieve local privilege elevation on a recent #Windows 11 […]
infosec.exchange
Original post on infosec.exchange
012
Reposted by Sam Thomas
Mathy Vanhoef @vanhoefm.bsky.social · 14/01/2025
After an embargo of 8 months, we are glad to finally share our USENIX Security '25 paper! We found more than 4 MILLION vulnerable tunneling servers by scanning the Internet. These vulnerable servers can be abused as proxies to launch DDoS attacks and possibly to access internal networks.
25725
Reposted by Sam Thomas
raptor @raptor.infosec.exchange.ap.brid.gy · 26/12/2024
2025 is just around the corner. If #LearningRust is among your New Year’s resolutions, I’ve got you. Following my ongoing #Rust series on the @hnsec blog (security.humanativaspa.it/tag/rust) and adding something along the way, in the next days I’ll recommend the learning resources […]
infosec.exchange
Original post on infosec.exchange
024
Reposted by Sam Thomas
raptor @raptor.infosec.exchange.ap.brid.gy · 20/12/2024
Type-based #Rust #cheatsheet 🔥 upsuper.github.io/rust-cheatsheet
upsuper.github.io
Basics - Rust cheat sheet
021
Reposted by Sam Thomas
HN Security @hnsec.infosec.exchange.ap.brid.gy · 10/12/2024
Hello Rustaceans! Our technical director @raptor is back at it. In this second installment of our #Rust series, “An offensive Rust encore”, he will guide you in bringing your skills to the next level by using a new PoC #RedTeaming tool as an excuse […]
infosec.exchange
Original post on infosec.exchange
033
Sam Thomas @xorpse.ghost.sh · 13/11/2024
To showcase this release, I've released parascope, a tool that simplifies weggli pattern scanning by adding a ruleset language and the ability to mass-scan source code and binaries (via idalib) in parallel! github.com/xorpse/paras...
recording of a parascope scan on a directory of binaries
165
Sam Thomas @xorpse.ghost.sh · 13/11/2024
We've (BINARLY) just released idalib v0.2.0, an update to our IDASDK Rust bindings. It includes many new features: bookmarks, comments, and plugins APIs, hex-rays support, and documentation! github.com/binarly-io/i... Thanks to our contributors: @yeggor.bsky.social @0xdea
github.com
GitHub - binarly-io/idalib: Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.0’s idalib
Idiomatic Rust bindings for the IDA SDK, enabling the development of standalone analysis tools using IDA v9.0’s idalib - binarly-io/idalib
021