Stéfan Le Berre - Heurs
@heurs.bsky.social
📤 20
📥 14
📝 2
Work at @ExaTrack, love rootkits ->
https://github.com/ExaTrack/Kdrill
I'm glad to share my talk at
@botconf.infosec.exchange.ap.brid.gy
2025! Do you want to know how we compare a sample with 150k others in seconds on
@exalyze.bsky.social
? This talk is made for you🚀 At the end, you'll get a hint on what's coming next for Exalyze 😉
youtube.com/watch?v=TS8X...
exalyze.io
loading . . .
10 Years of Large-Scale Malware Comparison: Going Deeper With Machoke
YouTube video by botconf eu
https://youtube.com/watch?v=TS8XO2EoBKM
6 months ago
0
4
3
reposted by
Stéfan Le Berre - Heurs
CyberTaters
9 months ago
#Podcast
#Potatosécurité
Épisode
#502
: détection vs. recherche de compromissions (suite de l'épisode
#491)
, avec
@heurs.bsky.social
www.nolimitsecu.fr/detection-vs...
0
0
1
reposted by
Stéfan Le Berre - Heurs
9 months ago
#Podcast
#Cybersécurité
Épisode #501 : détection vs. recherche de compromissions (suite de l'épisode #491), avec
@heurs.bsky.social
www.nolimitsecu.fr/detection-vs...
loading . . .
Détection vs Recherche de Compromissions : La discussion continue - NoLimitSecu
Épisode #502 – Détection vs Recherche : La discussion continue (épisode #491) Avec Stéfan LE BERRE
https://www.nolimitsecu.fr/detection-vs-recherche-de-compromissions-la-discussion-continue/
0
5
7
Kdrill update 📢 ARM64 support added, hunt those rootkits before they adapt to your Winows!
github.com/ExaTrack/Kdr...
loading . . .
GitHub - ExaTrack/Kdrill: Python tool to check rootkits in Windows kernel
Python tool to check rootkits in Windows kernel. Contribute to ExaTrack/Kdrill development by creating an account on GitHub.
https://github.com/ExaTrack/Kdrill
12 months ago
0
2
0
reposted by
Stéfan Le Berre - Heurs
Alexandre Borges
about 1 year ago
The nineth article (38 pages) of the Malware Analysis Series (MAS) is available on:
exploitreversing.com/2025/01/08/m...
Even though I haven't been on this subject for years, I promised I would write a series of ten articles, and the last one will be released next week (JAN/15).
#malware
0
5
3
reposted by
Stéfan Le Berre - Heurs
about 1 year ago
RULECOMPILE - Undocumented Ghidra decompiler rule language. A blog post about how frustration with poor decompilation led me to dive deep into Ghidra's decompiler to discover (and reverse-engineer) - an obscure, undocumented DSL
msm.lt/re/ghidra/ru...
#reverseengineering
#ghidra
0
14
9
reposted by
Stéfan Le Berre - Heurs
about 1 year ago
3+ YEARS of stealth! We uncovered new tactics used by the perfctl malware, including a userland rootkit & an SSH backdoor (a single SPACE in /etc/passwd!). More insights:
blog.exatrack.com/Perfctl-usin...
#cybersecurity
#threat_hunting
#linux
#infosec
#perfctl
#rootkit
#ssh
#exatrack
loading . . .
Perfctl malware exploiting exposed Portainer agent and using new SSH persistenceExaTrack
https://blog.exatrack.com/Perfctl-using-portainer-and-new-persistences/
0
10
6
you reached the end!!
feeds!
log in