ch
Feedback
Alaid TechThread

Alaid TechThread

前往频道在 Telegram

Vulnerability discovery, threat intelligence, reverse engineering, AppSec

显示更多
323
订阅者
无数据24 小时
无数据7 天
无数据30 天
帖子存档
ghidraMCP is an Model Context Protocol server for allowing LLMs to autonomously reverse engineer applications. It exposes numerous tools from core Ghidra functionality to MCP clients. https://github.com/LaurieWired/GhidraMCP

Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows https://connormcgarr.github.io/km-shadow-stacks/

The plugin provides a custom navigation interface within IDA. It examines execution paths from entry points, breaks down the binary into clusters of related functions, and highlights downstream behaviors and artifacts for quicker insights. XRefer can incorporate external data (e.g., API traces, capa results, user-defined xrefs) and provides path graphs for richer context. It integrates with Google's Gemini model to produce natural language descriptions of code relationships and behaviors. Additionally, XRefer can provide cluster based labels for functions, aiming to accelerate the manual static analysis process.
https://github.com/mandiant/xrefer

Safeliner - AI решение для исправления уязвимостей в коде #safeliner

Leveling Up Fuzzing: Finding more vulnerabilities with AI https://security.googleblog.com/2024/11/leveling-up-fuzzing-finding-more.html

Known Vulnerabilities of Open Source Projects: Where Are the Fixes? https://ieeexplore.ieee.org/document/10381645

Advanced%20Fuzzing%20With%20LibAFL%20@%20Ekoparty%202024.pdf.pdf4.69 MB

Pishi: Coverage guided macOS KEXT fuzzing https://r00tkitsmm.github.io/fuzzing/2024/11/08/Pishi.html

Lessons from the buzz: What have we learned from fuzzing the eBPF verifier https://lpc.events/event/18/contributions/1946/attachments/1473/3119/Lessons%20from%20the%20buzz%20-%20LPC.pdf

Securing the software commons Standards, Automation, and AI for a Resilient Open Source Future

FUZZING'24 Keynote: "Is 'AI' useful for fuzzing?" https://www.youtube.com/watch?v=4BPJXmrdmls

Introducing Java fuzz harness synthesis using LLMs https://blog.oss-fuzz.com/posts/introducing-java-auto-harnessing/

TROOPERS24: Fuzzing at Mach Speed: Uncovering IPC Vulnerabilities on MacOS https://www.youtube.com/watch?v=tZmollb8NXk

Exploiting the Windows Kernel via Malicious IPv6 Packets (CVE-2024-38063) https://malwaretech.com/2024/08/exploiting-CVE-2024-38063.html

Top Score on the Wrong Exam: On Benchmarking in Machine Learning for Vulnerability Detection https://arxiv.org/pdf/2408.12986

Transferring Backdoors between Large Language Models by Knowledge Distillation https://arxiv.org/pdf/2408.09878