@the_navsi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Security Researcher at █████████████ Strike First. Strike Hard. No Mercy.
Austin, TX
Joined April 2009
- Tweets977
- Following399
- Followers1.1K
- Likes157
navs retweeted
Cyber. Peacekeeping.
Do you think that United Nations should engage in cyber peacekeeping missions? If so, how should it look like and when it should be deployed? Also, are we even serious? :-) Also: "disarmament of software applications that
can be used for cyber warfare"! academic.oup.com/jcsl/articl…
navs retweeted
Replying to @windsheep_ @matalaz
We've got many "professional grade" customers who think otherwise.
navs retweeted
This getting 6k retweets is absolutely *hilarious* when you think about it. Hacker, comedian, master of irony... @mdowd is a true Renaissance man.
navs retweeted
A new vulnerability detection: Use of Uninitialized Memory. Using REVEN, it also works when it involves interprocess communication. A post to introduce the new addition to our series of vulnerability detection scripts:
url.tetrane.com/KfLyk/248d
navs retweeted
"I looked at this new Android exploit sample and it's either from a CTF or a nation-state attack." -- @maldr0id
navs retweeted
Did my experiment work? No. But did I learn from it? No. But did it help me grow as a scientist? Also no.
navs retweeted
pitch: like @TheFckingRecipe, but for bug advisories
navs retweeted
“Bond007”
You’re unable to view this Post because this account owner limits who can view their Posts. Learn more
navs retweeted
Honestly I’m probably going to get some backlash on this, but can the news articles that glorify that Apple hack stop calling @samwcyo et al “security researchers”. It significantly discounts actual security research.
navs retweeted
New blog entry: An Exhaustively-Analyzed IDB for ComRAT V4. This is one of the most thorough analyses I've ever done; certainly the largest. msreverseengineering.com/blo…
navs retweeted
Replying to @ruskin147
It is unfortunately common for many in academia to overweight the value of ideas & underweight bringing them to fruition. For example, the idea of going to the moon is trivial, but going to the moon is hard.
navs retweeted
Man people doing crime just aren't following any of the rules anymore, are they? What's the world coming to?
nitter.cf/tylerni7/status/129869…
This is just cheating: pay an employee $1M to install ransomware on a corporate network, then ask for a $5-10M ransom?
That's not even hacking! Where's the skill? the pizzazz?
Doesn't need to be 0days but at least find an unpatched system or phish someone!
zdnet.com/article/russian-ar…
navs retweeted
Over the past 5 years I have been building security programs based on and writing about Adversary-Based Threat Modeling and Risk Analysis. Now it's a training course! Let me know if you want your team to build and operate with adversary intelligence.
adversarybased.training/
navs retweeted
Ghidra's, and IDA 7.5's new, "folders" feature is incredibly useful for large-scale reverse engineering. I've found it especially provides clarity when organizing reconstructed data structures.
navs retweeted
Reinstalled my OS yesterday. Apologies to anyone who lost their persistence, and congratulations to anyone who kept theirs 💪
navs retweeted
when your company transitions from using personal credit cards to mandatory corporate cards for expensing... losing the perk of gaining cc points for work purchases. this picture summarizes my feelings. @the_navs
navs retweeted
Want to know how to escape the Chrome sandbox exploiting Android's Binder with CVE-2020-0041? Check out our latest post by @esanfelix and @jgrusko
labs.bluefrostsecurity.de/bl…