@MarkStyron

Believer. Husband. Father. Veteran. and Cybersecurity Researcher. My Tweets are my own.

Fayetteville
Joined September 2009
Mark Styron @mstyron@infosec.exchange retweeted
Free resource for anyone learning heap exploitation. Credit to @shellphish for maintaining how2heap, a practical collection of glibc heap exploitation techniques with small working PoCs across different libc versions. Fastbin, tcache, unlink, overlapping chunks, House techniques and more. github.com/shellphish/how2he… #ExploitDevelopment #VulnerabilityResearch #ReverseEngineering
2
85
507
16,329
Mark Styron @mstyron@infosec.exchange retweeted
Know every way to break a JWT. 38 pages, 47 techniques. brutelogic.net/ebooks/broken… With original research and tested payloads.
3
22
114
6,556
Mark Styron @mstyron@infosec.exchange retweeted
someone asked Beej how sockets work in C. he got tired of explaining it so in 1995 he put it all online: TCP, UDP, IPv4, IPv6, select(), poll(), and more free, practical, and still widely used
7
68
469
11,671
Mark Styron @mstyron@infosec.exchange retweeted
Replying to @ForbesTVNews
Rogue is BS. Nothing went rogue. People decided to leave security out of the equation. I wrote about this back in July. And due to all the FUD, I am writing a 3-part series on just a few things we can do NOW to control AI and prepare for ASI. 3l337consulting.com/blog/f/a… 3l337consulting.com/blog/f/c… 3l337consulting.com/ai/super… Part 3 should be out imminently.
1
1
1
16
Mark Styron @mstyron@infosec.exchange retweeted
If you're into malware analysis, reverse engineering or threat intelligence, bookmark this. @embee_research has built an incredible FREE archive of practical security research covering: • Ghidra + x64dbg • Malware unpacking + shellcode • Cobalt Strike analysis • API hashing + string decryption • PE-bear + Dumpulator • .NET malware + dnSpy • CyberChef + Python deobfuscation • YARA + Sigma • Qakbot, IcedID, AgentTesla, DarkGate + more • Passive DNS + infrastructure hunting • Censys / FOFA pivots • APT infrastructure tracking • URL hunting • Module stomping + API hash evasion A lot of this is hands-on research using real malware samples, not just theory. Also includes deep dives into campaigns like SideWinder and Gamaredon infrastructure hunting. Main site: embeeresearch.io/ Full archive: embeeresearch.io/index/ Huge credit to fellow Australian @embee_research / Matthew for making this research publicly available. #MalwareAnalysis #ReverseEngineering #ThreatIntel
1
101
599
21,649
Mark Styron @mstyron@infosec.exchange retweeted
**NEW** BHIS | Blog Want to learn how C2 beaconing really looks on the wire? Spin up three hosts, run Sliver, capture the traffic, and hunt it with Zeek and RITA. It's your personal playground for learning adversary behavior? Threat Hunting Home Lab: Your Personal Playground for Learning Adversary Behavior By: Faan Rossouw Published: 9/30/2026 Learn more: blackhillsinfosec.com/threat…
1
5
56
2,889
Mark Styron @mstyron@infosec.exchange retweeted
If you're learning exploit development, bookmark this. A FREE collection of hands-on exploit development tutorials covering: Linux + Windows buffer overflows ROP + defeating DEP ASLR + Windows mitigations Heap overflows Format string vulnerabilities Race conditions SEH exploitation x64 assembly ARM shellcode iPhone exploitation Created by @sambowne with @djhardb, @KaitlynGuru and @infosecirvin. Start here: samsclass.info/127/ED_2020.s… Excellent free resource for anyone getting into exploit development, binary exploitation and reverse engineering. #ExploitDevelopment #ReverseEngineering #Infosec
2
179
1,004
30,861
Mark Styron @mstyron@infosec.exchange retweeted
a professor at Illinois got frustrated with existing systems programming textbooks so he started a Wikibook with students helping write it it covers C, processes, threads, memory, networking, filesystems, scheduling, and security all in one free book
16
203
2
1,627
49,699
Congratulations Tim! This promotion is well deserved.
So much going on in life these days. This week I was promoted from SANS Principal Instructor to SANS Senior Instructor. As I started this journey in 2014, I would never have predicted to make it this far. Thank you to @SANSOffensive for the opportunity and platform, thank you to the many students that have participated in my classes, and thank you to everyone that has been part of my life and career that helped me get to where I am today.
1
35
Mark Styron @mstyron@infosec.exchange retweeted
Join us today at 12:30pm!
Join me on Friday, September 25th at 12:30PM for the next @offby1security stream with guest Tarun Koyalwar @KoyalwarTarun on "Watching Offensive AI Agents Work!" Thanks for helping us reach 50K subscribers! youtube.com/watch?v=WWQRirWA…
3
8
1,719
Mark Styron @mstyron@infosec.exchange retweeted
If you're into malware analysis or reverse engineering, bookmark this. @hasherezade has built an incredible collection of FREE research, tools, articles and talks covering: - Malware reverse engineering - PE internals + analysis - PE-bear - PE-sieve + HollowsHunter - Process injection + hollowing - Malware unpacking - Ransomware analysis - Custom malware formats - Rhadamanthys - Petya / NotPetya - Shellcode + in-memory implants - V8 JavaScript bytecode deobfuscation Her research archive goes back more than a decade, with everything from classic Windows malware analysis to Black Hat USA 2026 research. Projects: hasherezade.github.io/ Articles: hasherezade.github.io/articl… Talks + slides: speakerdeck.com/hshrzd Huge credit to @hasherezade for publishing so much of this work and tooling openly. Absolute rabbit hole for malware analysts, reverse engineers and threat researchers. #MalwareAnalysis #ReverseEngineering #Infosec
3
49
1
268
9,693
Mark Styron @mstyron@infosec.exchange retweeted
The most surprising thing with Opus 5.5 so far, is when you talk about doing something, build a complete plan, and the context of the discussion indicates the plan is decided… IT STARTS DOING WORK!! How much of my life has been wasted by Opus 4.8 and 5, agreeing, approving, confirming my approval, and finally yelling at it to just start the *bleeping* work already. @anthropic Opus 5.5 as it exists today may be the most perfect I have seen LLMs function. Thank you!
1
1
2
81
Mark Styron @mstyron@infosec.exchange retweeted
From your first buffer overflow to kernel exploitation. Free. pwn.college takes you from basic Linux commands all the way through reverse engineering, shellcoding, ROP chains, heap exploitation, format strings, race conditions, and kernel module exploitation. All hands-on. All in a browser-based workspace. Reverse engineering with IDA, Ghidra, Binary Ninja, and angr. User-mode exploitation through every modern mitigation bypass. Kernel exploitation covering stack overflows, heap corruption, and race conditions in kernel modules. One of the places I spent a long time on and still do. If you are serious about exploit development and vulnerability research, this is where you sharpen the fundamentals. YouTube lectures, live Twitch streams, and a Discord community to get unstuck. Free. No paywall. No signup wall. Pwn: pwn.college/ YouTube: youtube.com/pwncollege Created by @Zardus (Yan Shoshitaishvili), kanak (Connor Nelson), mahaloz (Zion Basque), Erik Trickel, Adam Doupé, Pascal-0x90, and frqmod at Arizona State University. #ExploitDevelopment #ReverseEngineering #InfoSec
3
75
1
420
16,142
Mark Styron @mstyron@infosec.exchange retweeted
If you work with Windows internals, reverse engineering or exploit development, bookmark this. @j00ru 's blog is one of the best FREE archives of low-level Windows security research online. It covers: Windows kernel internals Kernel exploitation Reverse engineering Memory corruption + infoleaks Win32k internals NT + Win32k syscall tables CSRSS APIs + internals Fuzzing + instrumentation Windows mitigations Conference talks Technical papers + research Exploit development Some of this research goes back more than 15 years and is still incredibly useful for understanding how Windows works under the hood. The site also maintains dedicated Windows syscall tables and CSRSS reference material. Absolute rabbit hole for anyone serious about Windows security. j00ru.vexillium.org/ #WindowsInternals #ReverseEngineering #ExploitDevelopment
5
94
546
16,395
Mark Styron @mstyron@infosec.exchange retweeted
Back in 2021 I wrote a "how to hack APIs" blog for Detectify. It ended up being one of the most-read things I've written that year, but APIs have changed a lot since then: GraphQL, AI-generated endpoints, all of it. So I rewrote the whole thing for 2026. Check it out👇
2
42
214
9,397
Mark Styron @mstyron@infosec.exchange retweeted
Looking forward to this event! If you’re going to be there come find me to say hi.
Just two weeks until OAIC! Will Schroeder, Lee Chagolla-Christensen, Becca Lynch, Matthew Nickerson, Max Bazalii, and Aaron Grattafiori are up the first half of day 1! See the full agenda at offensiveaicon.com/schedule
1
18
2,150
Mark Styron @mstyron@infosec.exchange retweeted
On 15 September 2026 Joshua released a new book "Dynamic Incident Response." I am looking forward to reading this book. The book is Free in many different formats. Enjoy!
Today at noon EDT I'm launching a book I've been working on for 20 months: Dynamic Incident Response, an iterative IR framework designed for how security teams actually work. Free in all formats. Join me for the launch today: sans.org/engage/dynamic-inci…
1
3
28
Mark Styron @mstyron@infosec.exchange retweeted
Join me on Friday, September 25th at 12:30PM for the next @offby1security stream with guest Tarun Koyalwar @KoyalwarTarun on "Watching Offensive AI Agents Work!" Thanks for helping us reach 50K subscribers! youtube.com/watch?v=WWQRirWA…
1
16
3
67
6,475
Mark Styron @mstyron@infosec.exchange retweeted
Breaking Windows: Exploring Security Through Kernel Drivers nitter.cf/i/broadcasts/1oKMvNMny…
34
94
5,196
Mark Styron @mstyron@infosec.exchange retweeted
Air-gapped AI security deserves real threat modeling. BitWhisper proves thermal channels exist, but not that modern AI containment is futile.
4
2
4
25,008