Веб-версияОткрыть в Telegram
CCafe Security

Cafe Security

@cafe_security · канал · Технологии · в индексе с 2026-04-17
1 221подписчиков+2 за неделю
210постов в индексе
M
Mohammad
Файл
p153-yunhe.pdf · 210 КБ · нажмите — покажем
Virtual Machine Showdown: Stack Versus Registers #dalvik #art #jvm #vm @cafe_security
20 · 995 ·
M
Mohammad
Файл
20131230-appelbaum-nsa_ant_catalog.PDF · 6.9 МБ · нажмите — покажем
NSA ANT Product Data #nsa #implant پ.ن: قراره موارد بسیار جالب و ترسناکی ببینید :) @cafe_security
30 · 952 ·
Mohammad
Ссылка
нажмите — покажем
یکی از ابزار هایی که من مدت هاست بشخصه در بحث کشف آسیب پذیری و مباحث مرتبط استفاده می کنم ابزار dynapstalker هستش این ابزار مدت ها هست اپدیت نشده و من نسخه سازگار با اخرین نسخه ایدا رو داخل گیستم قرار دادم. https://gist.github.com/binophism/4ef99f67d815efbafc20119fa06754cb #VR @cafe_security
12 · 894 ·
M
Mohammad
Файл
nbnfi-fe2022101161598 (1).pdf · 743 КБ · нажмите — покажем
A TSX-Based KASLR Break: Bypassing UMIP and Descriptor-Table Exiting #KASLR #UMIP @cafe_security
9 · 778 ·
M
Mohammad
Фотография
нажмите — покажем
Slides and recordings for our @FOSDEM talks are up! Join [Björn Ruytenberg] and [Sina Karvandi] for an in-depth introduction into @HyperDbg 's features and internals, or find out what's the latest in anti-anti-debugging techniques and HV transparency for malware reversing: - https://fosdem.org/2026/schedule/event/APB9WC-mbec_slat_and_hyperdbg_hypervisor-based_kernel-_and_user-mode_debugging/ - https://fosdem.org/2026/schedule/event/CDPRDX-invisible_hypervisors_debugging_with_hyperdbg/
7 · 700 ·
M
Mohammad
[  42.1337] #security: EXAM: Exploiting Exclusive System-Level Cache in Apple M-Series SoCs for Enhanced Cache Occupancy Attacks https://arxiv.org/html/2504.13385v1 Apparently the shared cache inside Apple M chips (the System Level Cache that both CPU and GPU use) can accidentally act like a little "activity meter" for the whole system. If you measure how busy or full it gets, you can infer what other parts of the chip are doing even if you're running somewhere else. The authors use that signal for things people don't expect a cache to reveal, like guessing which websites are being loaded from the pattern alone and even getting rough clues about what's on screen based on how the GPU renders frames. It wraps up with an "add noise" style mitigation that tries to blur the leak without much overhead.
4 · 835 ·
Mohammad
Файл
SentinelInstaller_windows_64bit_v25_1_4_434.msi · 57.9 МБ · нажмите — покажем
Token: eyJ1cmwiOiAiaHR0cHM6Ly9ldWNlMS0xMDkuc2VudGluZWxvbmUubmV0IiwgInNpdGVfa2V5IjogImNkZWIxMGEwYmM4ZGUwMTU3ZjliZGRmNjdkMDJmOTE2NzE0NjMwNzEyNGIxNTlhYzcwZGRmYWI2OGZiYzEzNGEifQ==
13 · 543 ·
Mohammad
Kernel Karnage Part 1: Patching Windows Kernel Callbacks to Disable EDR from a Driver ———————————————————————————- The first post of NVISO Labs’ Kernel Karnage series walks through the opening move of an EDR-bypass research project: write a small Windows kernel driver, locate the undocumented PspCreateProcessNotifyRoutine callback array that the OS uses to deliver process-creation notifications, and patch the EDR’s registered callback out of it. Process-creation callbacks are one of the load-bearing telemetry mechanisms modern EDR products depend on — remove them and a wide class of behavioural detections go dark. https://core-jmp.org/2026/06/kernel-karnage-part-1-patching-windows-kernel-callbacks-edr-bypass/ @cafe_security
11 · 641 ·
Mohammad
Ссылка
нажмите — покажем
volatility3-ai-triage https://github.com/zyekhabdul/volatility3-ai-triage volatility3-ai-triage performs high-utility memory triage by executing Volatility 3 plugins in parallel, cross-correlating raw memory artifacts across plugins, detecting advanced 2026 evasion techniques, and generating deterministic SIEM JSON / STIX 2.1 Threat Intel alongside executive Markdown & HTML Triage Reports via Local LLMs (Ollama) or Cloud APIs (Gemini, OpenAI). @cafe_security
10 · 672 ·

Открытая публичная лента из поискового индекса ChatCrawler — «Google по публичному Telegram»; обновляется по мере обхода площадки. Время — UTC.

Только публичный контент, официальный API Telegram. О проекте · Вопросы · Чего мы не делаем · Убрать страницу из выдачи · Каталог · Поиск · Как мы считаем