@MarkStyroni
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States Android App
Account-level information from X, not a live location or the device used for a specific post.
Believer. Husband. Father. Veteran. and Cybersecurity Researcher. My Tweets are my own.
Fayetteville
Joined September 2009
- Tweets6.5K
- Following696
- Followers270
- Likes8.5K
Free resource for anyone learning heap exploitation.
Credit to @shellphish for maintaining how2heap, a practical collection of glibc heap exploitation techniques with small working PoCs across different libc versions.
Fastbin, tcache, unlink, overlapping chunks, House techniques and more.
github.com/shellphish/how2he…
#ExploitDevelopment #VulnerabilityResearch #ReverseEngineering
Mark Styron @mstyron@infosec.exchange retweeted
Know every way to break a JWT.
38 pages, 47 techniques.
brutelogic.net/ebooks/broken…
With original research and tested payloads.
Mark Styron @mstyron@infosec.exchange retweeted
someone asked Beej how sockets work in C. he got tired of explaining it
so in 1995 he put it all online: TCP, UDP, IPv4, IPv6, select(), poll(), and more
free, practical, and still widely used
Mark Styron @mstyron@infosec.exchange retweeted
Replying to @ForbesTVNews
Rogue is BS. Nothing went rogue. People decided to leave security out of the equation. I wrote about this back in July. And due to all the FUD, I am writing a 3-part series on just a few things we can do NOW to control AI and prepare for ASI.
3l337consulting.com/blog/f/a…
3l337consulting.com/blog/f/c…
3l337consulting.com/ai/super…
Part 3 should be out imminently.
If you're into malware analysis, reverse engineering or threat intelligence, bookmark this.
@embee_research has built an incredible FREE archive of practical security research covering:
• Ghidra + x64dbg
• Malware unpacking + shellcode
• Cobalt Strike analysis
• API hashing + string decryption
• PE-bear + Dumpulator
• .NET malware + dnSpy
• CyberChef + Python deobfuscation
• YARA + Sigma
• Qakbot, IcedID, AgentTesla, DarkGate + more
• Passive DNS + infrastructure hunting
• Censys / FOFA pivots
• APT infrastructure tracking
• URL hunting
• Module stomping + API hash evasion
A lot of this is hands-on research using real malware samples, not just theory.
Also includes deep dives into campaigns like SideWinder and Gamaredon infrastructure hunting.
Main site:
embeeresearch.io/
Full archive:
embeeresearch.io/index/
Huge credit to fellow Australian @embee_research / Matthew for making this research publicly available.
#MalwareAnalysis #ReverseEngineering #ThreatIntel
Mark Styron @mstyron@infosec.exchange retweeted
**NEW** BHIS | Blog
Want to learn how C2 beaconing really looks on the wire? Spin up three hosts, run Sliver, capture the traffic, and hunt it with Zeek and RITA. It's your personal playground for learning adversary behavior?
Threat Hunting Home Lab: Your Personal Playground for Learning Adversary Behavior By: Faan Rossouw
Published: 9/30/2026
Learn more: blackhillsinfosec.com/threat…
If you're learning exploit development, bookmark this.
A FREE collection of hands-on exploit development tutorials covering:
Linux + Windows buffer overflows
ROP + defeating DEP
ASLR + Windows mitigations
Heap overflows
Format string vulnerabilities
Race conditions
SEH exploitation
x64 assembly
ARM shellcode
iPhone exploitation
Created by @sambowne with @djhardb, @KaitlynGuru and @infosecirvin.
Start here: samsclass.info/127/ED_2020.s…
Excellent free resource for anyone getting into exploit development, binary exploitation and reverse engineering.
#ExploitDevelopment #ReverseEngineering #Infosec
Mark Styron @mstyron@infosec.exchange retweeted
a professor at Illinois got frustrated with existing systems programming textbooks
so he started a Wikibook with students helping write it
it covers C, processes, threads, memory, networking, filesystems, scheduling, and security
all in one free book
Congratulations Tim! This promotion is well deserved.
So much going on in life these days. This week I was promoted from SANS Principal Instructor to SANS Senior Instructor. As I started this journey in 2014, I would never have predicted to make it this far. Thank you to @SANSOffensive for the opportunity and platform, thank you to the many students that have participated in my classes, and thank you to everyone that has been part of my life and career that helped me get to where I am today.
Mark Styron @mstyron@infosec.exchange retweeted
Join us today at 12:30pm!
Join me on Friday, September 25th at 12:30PM for the next @offby1security stream with guest Tarun Koyalwar @KoyalwarTarun on "Watching Offensive AI Agents Work!"
Thanks for helping us reach 50K subscribers!
youtube.com/watch?v=WWQRirWA…
If you're into malware analysis or reverse engineering, bookmark this.
@hasherezade has built an incredible collection of FREE research, tools, articles and talks covering:
- Malware reverse engineering
- PE internals + analysis
- PE-bear
- PE-sieve + HollowsHunter
- Process injection + hollowing
- Malware unpacking
- Ransomware analysis
- Custom malware formats
- Rhadamanthys
- Petya / NotPetya
- Shellcode + in-memory implants
- V8 JavaScript bytecode deobfuscation
Her research archive goes back more than a decade, with everything from classic Windows malware analysis to Black Hat USA 2026 research.
Projects:
hasherezade.github.io/
Articles:
hasherezade.github.io/articl…
Talks + slides:
speakerdeck.com/hshrzd
Huge credit to @hasherezade for publishing so much of this work and tooling openly.
Absolute rabbit hole for malware analysts, reverse engineers and threat researchers.
#MalwareAnalysis #ReverseEngineering #Infosec
Mark Styron @mstyron@infosec.exchange retweeted
The most surprising thing with Opus 5.5 so far, is when you talk about doing something, build a complete plan, and the context of the discussion indicates the plan is decided… IT STARTS DOING WORK!!
How much of my life has been wasted by Opus 4.8 and 5, agreeing, approving, confirming my approval, and finally yelling at it to just start the *bleeping* work already.
@anthropic Opus 5.5 as it exists today may be the most perfect I have seen LLMs function. Thank you!
From your first buffer overflow to kernel exploitation. Free.
pwn.college takes you from basic Linux commands all the way through reverse engineering, shellcoding, ROP chains, heap exploitation, format strings, race conditions, and kernel module exploitation. All hands-on. All in a browser-based workspace.
Reverse engineering with IDA, Ghidra, Binary Ninja, and angr. User-mode exploitation through every modern mitigation bypass. Kernel exploitation covering stack overflows, heap corruption, and race conditions in kernel modules.
One of the places I spent a long time on and still do. If you are serious about exploit development and vulnerability research, this is where you sharpen the fundamentals.
YouTube lectures, live Twitch streams, and a Discord community to get unstuck.
Free. No paywall. No signup wall.
Pwn: pwn.college/
YouTube: youtube.com/pwncollege
Created by @Zardus (Yan Shoshitaishvili), kanak (Connor Nelson), mahaloz (Zion Basque), Erik Trickel, Adam Doupé, Pascal-0x90, and frqmod at Arizona State University.
#ExploitDevelopment #ReverseEngineering #InfoSec
If you work with Windows internals, reverse engineering or exploit development, bookmark this.
@j00ru 's blog is one of the best FREE archives of low-level Windows security research online.
It covers:
Windows kernel internals
Kernel exploitation
Reverse engineering
Memory corruption + infoleaks
Win32k internals
NT + Win32k syscall tables
CSRSS APIs + internals
Fuzzing + instrumentation
Windows mitigations
Conference talks
Technical papers + research
Exploit development
Some of this research goes back more than 15 years and is still incredibly useful for understanding how Windows works under the hood. The site also maintains dedicated Windows syscall tables and CSRSS reference material.
Absolute rabbit hole for anyone serious about Windows security.
j00ru.vexillium.org/
#WindowsInternals #ReverseEngineering #ExploitDevelopment
Mark Styron @mstyron@infosec.exchange retweeted
Back in 2021 I wrote a "how to hack APIs" blog for Detectify. It ended up being one of the most-read things I've written that year, but APIs have changed a lot since then: GraphQL, AI-generated endpoints, all of it.
So I rewrote the whole thing for 2026.
Check it out👇
Mark Styron @mstyron@infosec.exchange retweeted
Looking forward to this event! If you’re going to be there come find me to say hi.
Just two weeks until OAIC! Will Schroeder, Lee Chagolla-Christensen, Becca Lynch, Matthew Nickerson, Max Bazalii, and Aaron Grattafiori are up the first half of day 1!
See the full agenda at offensiveaicon.com/schedule
Mark Styron @mstyron@infosec.exchange retweeted
On 15 September 2026 Joshua released a new book "Dynamic Incident Response." I am looking forward to reading this book. The book is Free in many different formats. Enjoy!
Today at noon EDT I'm launching a book I've been working on for 20 months: Dynamic Incident Response, an iterative IR framework designed for how security teams actually work. Free in all formats.
Join me for the launch today: sans.org/engage/dynamic-inci…
Mark Styron @mstyron@infosec.exchange retweeted
Join me on Friday, September 25th at 12:30PM for the next @offby1security stream with guest Tarun Koyalwar @KoyalwarTarun on "Watching Offensive AI Agents Work!"
Thanks for helping us reach 50K subscribers!
youtube.com/watch?v=WWQRirWA…
Mark Styron @mstyron@infosec.exchange retweeted
Breaking Windows: Exploring Security Through Kernel Drivers nitter.cf/i/broadcasts/1oKMvNMny…