Yarden Shafir's Avatar

Yarden Shafir

@yardenshafir

A circus artist with a visual studio license

1,197
Followers
35
Following
55
Posts
04.05.2023
Joined
Posts Following

Latest posts by Yarden Shafir @yardenshafir

Post image

Registration is open to all RECon classes!

As usual, I’ll be teaching Windows Internals. This is the only time this year that the class is offered in North America 😊

And if windows isn’t your thing, there are lots of other great classes!

recon.cx/2026/en/trai...

31.01.2026 15:34 πŸ‘ 4 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

Haven’t uploaded them but happy to do that if you find them useful on their own :)

29.05.2025 16:38 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
BlueHat IL 2025 - Yarden Shafir - Look, Maβ€”No Privileges! How Windows Gives You Kernel Pointers...
BlueHat IL 2025 - Yarden Shafir - Look, Maβ€”No Privileges! How Windows Gives You Kernel Pointers... YouTube video by Microsoft Israel R&D Center

Looks like BlueHatIL talks are online now, so here’s my talk for anyone who wanted to learn about the latest episode of KASLR and couldn’t make it: www.youtube.com/watch?v=Dk2r...

29.05.2025 01:30 πŸ‘ 9 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0

I wonder if Google maps can give me driving directions to TraceView, Tennessee

25.04.2025 18:53 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

AI search engines are the future

25.04.2025 17:54 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Microsoft threat actor found in the wild

07.04.2025 05:17 πŸ‘ 7 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

To me this looks like an oversight by Microsoft, not an intentional thing, but I’m not sure windows defender ever blocked any drivers through the ELAM callback so I don’t know if this changes much.

Other EDRs: do you use the ELAM blocking functionality or only use it for the cert?

03.04.2025 10:13 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Wdboot.sys driver entry, function is empty and has no functionality.

Wdboot.sys driver entry, function is empty and has no functionality.

For about a year now, WdBoot.sys essentially does nothing. Microsoft installs 2 versions:
- \System32\drivers\wdboot.sys is the β€œfull”, functional version
- \System32\drivers\wd\wdboot.sys is the β€œempty” version, which is the one being updated and loaded.

Does anyone know the reason behind this?

03.04.2025 10:12 πŸ‘ 2 πŸ” 1 πŸ’¬ 2 πŸ“Œ 0

The dying words of the American empire will be β€œI don’t think this code does anything. I’ll go ahead and delete that.”

29.03.2025 04:47 πŸ‘ 17 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Oh look they’re going to vibe program the SSA systems. I’m sure this will be perfectly fine and will cause no issues.

29.03.2025 04:46 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Knowing they eat steak makes them even scarier

22.03.2025 01:21 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Kookaburra

Kookaburra

This cute little thing sounds like a witch laughing in a dark forest and has tried to kill me twice so far

20.03.2025 14:03 πŸ‘ 10 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

I was told Australia is scary but didn’t expect to land and immediately get threatened by a public bus

16.03.2025 02:04 πŸ‘ 7 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Windows is going through some stuff right now

06.03.2025 21:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
Blog: Zen and the Art of Microcode Hacking This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.

"Zen and the Art of Microcode Hacking"

Tragic signature bypass enables custom microcode loading on AMD processors, and a tool to do it. The blog is extremely well written and provides concise explanations of topics mentioned + plenty of resources! A must read.

bughunters.google.com/blog/5424842...

06.03.2025 02:32 πŸ‘ 34 πŸ” 9 πŸ’¬ 0 πŸ“Œ 0

Small anecdote about thread priorities and throttling on Windows 11:
I’m downloading a large file.
Estimated time left: 28 minutes.
Open notepad, put it as the front window. Download time left: 57 minutes.
Close notepad, browser back in front. Time left: 27 minutes.

06.03.2025 20:21 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

I’m not saying you definitely have to go to @BlueHatIL this year, I’m just letting you know it’s free, by the beach and I’ll be there dropping kernel pointers to anyone who asks nicely

05.03.2025 23:07 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Meet Rayhunter: A New Open Source Tool from EFF to Detect Cellular Spying Rayhunter is a new open source tool we’ve created that runs off an affordable mobile hotspot that we hope empowers everyone, regardless of technical skill, to help search out cell-site simulators (CSS...

I work with cool people who do cool things: www.eff.org/deeplinks/20...

05.03.2025 22:32 πŸ‘ 325 πŸ” 104 πŸ’¬ 14 πŸ“Œ 9
Post image

Celebrating flat fuck Friday

28.02.2025 21:21 πŸ‘ 10 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Wanted to live tweet so bad but also didn’t wanna look away from the show it was so good. And the best singer in this was Janet!

20.02.2025 18:03 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Not that I saw but there were some of the usual shout outs and the narrator responded to all of them

19.02.2025 21:25 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

β€œIt was a strange night… how strange? As strange as the strangest thing going through Trump’s head”

19.02.2025 20:19 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

This is a full theatre production, live singing and all. This is everything I could ever ask for.

The narrator is brilliant and I’m crying laughing.

19.02.2025 20:19 πŸ‘ 1 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0
Post image

Going to a Rocky Horror show in a quiet UK town and the crowd is almost entirely old British people so I’m expecting an incredible time

19.02.2025 19:33 πŸ‘ 7 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0
BlueHat IL 2025- Congratulations- your submission to the main hall was accepted!

BlueHat IL 2025- Congratulations- your submission to the main hall was accepted!

πŸŽ‰πŸŽ‰

16.02.2025 08:56 πŸ‘ 10 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image Post image

More baking!

09.02.2025 18:15 πŸ‘ 6 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Every single Canadian stereotype is correct. It is -4c (24f) today and I've seen one people walking around in shorts and another one in a short-sleeved t-shirt. Not a single person is wearing a hat.

07.02.2025 19:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image Post image

Did a bit of baking this weekend

02.02.2025 14:20 πŸ‘ 5 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Of course!

31.01.2025 15:30 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Good morning

29.01.2025 16:35 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0