VSEC Academy
Ir al canal en Telegram
برگزاری دوره های تخصصی امنیت اطلاعات. ارائه ابزارهای رایگان و تجاری ( اختصاصی ) در خصوص حفظ حریم خصوصی و امنیت اطلاعات. پشتیبان آکادمی : https://t.me/VSEC_Support
Mostrar más2 502
Suscriptores
Sin datos24 horas
-27 días
+1730 días
Carga de datos en curso...
Canales Similares
Nube de Etiquetas
Menciones Entrantes y Salientes
---
---
---
---
---
---
Atraer Suscriptores
octubre '26oct '26
octubre '26
+1
en 0 canales
septiembre '26
+47
en 1 canales
Get PRO
agosto '26
+50
en 0 canales
Get PRO
julio '26
+82
en 2 canales
Get PRO
junio '26
+52
en 0 canales
Get PRO
mayo '26
+30
en 0 canales
Get PRO
abril '26
+13
en 0 canales
Get PRO
marzo '26
+8
en 0 canales
Get PRO
febrero '26
+246
en 1 canales
Get PRO
enero '26
+27
en 0 canales
Get PRO
diciembre '25
+111
en 2 canales
Get PRO
noviembre '25
+45
en 2 canales
Get PRO
octubre '25
+83
en 1 canales
Get PRO
septiembre '25
+88
en 2 canales
Get PRO
agosto '25
+113
en 1 canales
Get PRO
julio '25
+89
en 1 canales
Get PRO
junio '25
+59
en 0 canales
Get PRO
mayo '25
+97
en 3 canales
Get PRO
abril '25
+67
en 0 canales
Get PRO
marzo '25
+73
en 1 canales
Get PRO
febrero '25
+58
en 0 canales
Get PRO
enero '25
+81
en 0 canales
Get PRO
diciembre '24
+113
en 0 canales
Get PRO
noviembre '24
+72
en 0 canales
Get PRO
octubre '24
+157
en 0 canales
Get PRO
septiembre '24
+75
en 0 canales
Get PRO
agosto '24
+83
en 0 canales
Get PRO
julio '24
+84
en 0 canales
Get PRO
junio '24
+123
en 1 canales
Get PRO
mayo '24
+71
en 1 canales
Get PRO
abril '24
+67
en 0 canales
Get PRO
marzo '24
+124
en 0 canales
Get PRO
febrero '24
+345
en 0 canales
Get PRO
enero '24
+184
en 0 canales
Get PRO
diciembre '23
+284
en 0 canales
Get PRO
noviembre '23
+177
en 2 canales
Get PRO
octubre '23
+126
en 0 canales
Get PRO
septiembre '23
+77
en 0 canales
Get PRO
agosto '23
+50
en 0 canales
Get PRO
julio '23
+133
en 0 canales
| Fecha | Crecimiento de Suscriptores | Menciones | Canales | |
| 01 octubre | +1 |
Publicaciones del Canal
دوست دارید تو حوزه امنیت اطلاعات وارد بشید ؟ فارغ از اینکه شبکه " ایران اینترنشنال " دروغ گو هستش یا خیر ، پادشاهی خواه هستش یا خیر ، اصلا" بد هست یا خیر ؛ قبلش حتما" این مستند رو تماشا کنید....
https://www.youtube.com/watch?v=VsNSTvBX2eg
| 2 | Lockjaw - Advanced Windows C2 Framework (v0.2.15)
Lockjaw is an advanced, modular command-and-control (C2) framework engineered for red team engagements, adversarial simulations, and stealth operations. It utilizes a modern split-language architecture: a high-concurrency Rust Teamserver coupled with an evasive, dependency-free Zig implant and pure-assembly position-independent code (PIC) stagers.
https://github.com/g13net/lockjaw | 241 |
| 3 | خیلی با خودم کلنجار رفتم که این پروژه رو پابلیک بکنم یا نه
چون میترسیدم ازش سوء استفاده بشه ولی خب برای اینکه حداکثر جلوگیری رو کرده باشم بخش های حیاتی و واقعا" مفید رو حذف کردم و فقط بخش هایی رو گذاشتم بمونه تا کسانی که دوست دارن چیزی ازش یاد بگیرن بتونن ( نه افرادی که صرفا" دنبال ابزار آماده برای پنهان سازی بدافزار خودشون هستن )
حالا این برنامه چیکار میکنه ؟ به زبان ساده کدهای پاورشل شما رو به یک زبان میانی تبدیل میکنه که فقط فایل اجرایی ما اون رو میفهمه و میتونه اون تفسیر و اجرا کنه ( از طریق اجرا داخل یک ماشین مجازی Stack-Based ) اینطوری هم تحلیل برنامه کمی سخت تر میشه و نمیشه فقط با خوندن کد متوجه شد جریان از چه قراره و اینکه دیگه مثل Invoke-Obfuscation نمیشه بصورت ایستا کد مبهم شده رو رمزگشایی/ابهام زدایی کرد و حتما" نیازمند تحلیل منطق ماشین مجازی هستش ( رمزنگاری اینجا خیلی ساده است و یک XOR با بایت های از پیش تعریف شده هستش و رمزنگاری تصادفی رو به دلایلی که پیشتر عرض کردم حذف کردم ) ، از دیگر مزایای این برنامه اینه که باعث میشه در عملیات Red Teaming محتوای Payload که در واقع همون کد پاورشل باشه یه سری اطلاعات درهم شده باشه که فقط و فقط برای فایل اجرایی قابل درک هستش حتی اگر رمزنگاری روی اون اعمال هم نشه ! بنابراین ارسال اون در شبکه فعلا" ( تا زمان شناسایی ) بی خطر خواهد بود ( قابل توجه SOC کار ها !!! ) و برای اجرا هم دیگه پروسه پاورشل اجرا نمیشه ( بازم قابل توجه SOC کارها ).
امیدوارم که این کد به درد علاقه مندان حوزه امنیت سایبری بخوره و بتونن ازش استفاده بکنن. با این قیمت دلار و تورم افسار گسیخته و وضعیت نامعلوم آینده کشور، فعلا" دوره برگزار نمیکنم ( حداقل تا یکی دو هفته ) و سعی دارم به این شکل تجربیات خودم رو منتقل کنم باشد که رستگار شویم و حداقل یک خدا پدرت و بیامرزه برام باقی بمونه.
لینگ گیت هاب پروژه : https://github.com/NIKJOO/PS2VM | 341 |
| 4 | Just open-sourced a Delphi 10.2 project I’ve been working on: Go_VM — a Go source virtualizer & obfuscator.
Most code-protection tools focus on binary-level techniques. I took a different route: compile selected Go functions into a custom stack-based VM bytecode, apply several obfuscation passes, and emit a fully self-contained, compilable Go program that still runs with the standard toolchain.
What it does
Virtualizes pure computational functions (arithmetic, control flow, loops, locals, calls)
Encrypts constants at compile time and decrypts them only inside the VM
Applies control-flow flattening, instruction substitution, and safe opaque predicates
Keeps complex or unsupported functions native and lets the VM call them when needed
Produces a single .go file that includes the complete VM runtime — no external dependencies beyond the Go standard library
Why Delphi?
I wanted a fast, native Windows console tool with full control over the compiler and emitter pipeline. Delphi 10.2 turned out to be an excellent fit for building a reliable, dependency-free binary that developers can drop into their workflow.
The project includes careful handling of jump targets and loop back-edges so that virtualized for loops remain correct after obfuscation — a common source of subtle bugs in this class of tools.
If you work with Go, software protection, or just enjoy seeing classic compiler techniques applied in a practical setting, feel free to check it out, star it, or open an issue.
Educational / research use. Obfuscation is only one layer — always pair it with proper architecture and server-side checks.
🐱 https://github.com/NIKJOO/Golan-REVoid | 561 |
| 5 | معرفی VSEC-REVoid – موتور پیشرفته مبهمسازی کد
با افتخار نسخه محدود و دموی ابزار VSEC-REVoid را معرفی میکنم؛ ابزاری قدرتمند برای محافظت از کد که توابع انتخابشده C/C++ را به یک ماشین مجازی پلیمورفیک و منحصربهفرد تبدیل میکند.
هر تابع مجازیسازیشده seed، نگاشت opcode، هندلرهای رمزنگاریشده، توپولوژی کنترلفلو و مکانیزمهای ضدتحلیل مخصوص به خود را دریافت میکند. نتیجه یک باینری بهشدت مبهمسازیشده است که مهندسی معکوس آن بسیار دشوار میشود.
قابلیتهای کلیدی:
• ماشین مجازی پلیمورفیک منحصربهفرد برای هر تابع
• رمزنگاری چندلایه کد و زنجیرهسازی هندلرها
• مبهمسازی پیشرفته کنترلفلو (BCF، Opaque Predicate، Nested Mini-VM)
• ضدشبیهسازی، Runtime Attestation و بررسی یکپارچگی
• اجرای ترکیبی هوشمند Native + VM
• موتور متامورفیک با MBA و Data-dependent Salt
توجه مهم: این نسخه دمو و محدودشده (Beta 1.0) است.
بسیاری از قابلیتها هنوز در حال توسعه هستند. لطفاً آن را تست کنید و هرگونه باگ، کرش یا رفتار غیرمنتظره را گزارش دهید تا بتوانیم ابزار را تکمیل و پایدار کنیم.
پس از رسیدن به نسخه پایدار و کامل، سورسکد کامل پروژه بهصورت عمومی منتشر خواهد شد.
اگر در حوزه محافظت نرمافزار، مقاومت در برابر مهندسی معکوس یا تکنیکهای پیشرفته مبهمسازی فعالیت دارید، این دمو را امتحان کنید و نظرات خود را با ما در میان بگذارید.
🐱 گیت هاب : https://github.com/NIKJOO/VSEC-REVoid
⛔️ معرفی در یوتیوب : https://www.youtube.com/watch?v=2qyaRCpZgKs | 558 |
| 6 | wait for first beta release of tool 🔥 | 164 |
| 7 | 🔬 🙂 A New Challenge for Binary Decompilers
I’ve been working on a research project focused on anti-analysis techniques for native binaries, and I’m excited to share an interesting result.
I developed a tool that can cause the decompilation process to fail or become impractical in both IDA Pro and Binary Ninja.
The screenshots below show the same binary being analyzed by the two tools:
Binary Ninja: the target function becomes extremely complex to analyze, resulting in a massive and highly tangled control-flow graph.
IDA Pro: decompilation fails with a “Function too big” limitation.
The goal of this research is not simply to make a binary “look complicated”, but to explore how modern reverse-engineering tools handle adversarial native code and analysis-resistant constructs.
This opens up some interesting questions:
How far can we push static analysis before automated decompilation becomes unreliable or infeasible?
I’m currently working on refining the technique, improving its reliability, and testing it against different analysis engines and binary architectures.
🚀 I’m also planning to release the tool publicly and completely free of charge in the near future, so researchers, reverse engineers, and security professionals can experiment with it and evaluate its effectiveness themselves.
More technical details and the public release will be coming soon. | 728 |
| 8 | In memory of Mahsa Amini 🖤
https://crackmes.one/crackme/6aa4aaeb3b246e477b6c0bf4 | 740 |
| 9 | فایل CTF که داخل ویدیو در موردش صحبت شده. | 940 |
| 10 | آیا هوش مصنوعی میتونه مهندسی معکوس رو اتوماتیک انجام بده ؟
آیا میتونم یه فایل بهش بدم و برام تحلیل کنه و همه چیز رو تر و تمیز بهم تحویل بده ؟
آیا میتونه CTF ها رو جای من حل کنه منم بشینم تماشا کنم ؟!
جواب خلاصه : فعلا" خیر
ولی تو ویدیو کامل توضیح دادم البته با یه شرط !
طرفداران دو آتیشه AI که مخالف عرض بنده هستن ، چالش رو با AI حل کنن ، رایت آپش رو عمومی کنن تا سورس کد ابزاری که تو ویدیو در موردش صحبت میشه ( مبهم ساز سورس کد ) رو با لایسنس MIT داخل گیت هاب قرار بدم.
https://youtu.be/spAIGxlHZwc | 972 |
| 11 | خیلی کم پیش اومده که تو hashtagالکامپ شرکت کنم ولی اگه یکی دو روز زودتر به این hashtagباگ از hashtagپادویش میرسیدم قطعا" میرفتم ( البته اگر حضور داشتن ) تا بپرسم واقعا" با چه تفکری دارن این واسه این برنامه پول خرج میکنن ؟!
پ.ن : ویدیو بر خلاف باقی ویدیو ها که فقط موزیک متن داشت دارای توضیحات صوتی هستش. | 1 039 |
| 12 | 🔥 GoVMProtect is an innovative Go source-code virtualization and obfuscation tool that translates selected Golang functions into custom VM bytecode, embeds a lightweight virtual machine, and removes the original function implementation. It addresses a gap in Go’s protection ecosystem by making reverse engineering significantly more difficult while preserving the original function signatures and application behavior.
Built for professional projects, GoVMProtect supports control flow, arithmetic, collections, method calls, type conversions, and multi-function transformation through an automated Python-based toolchain.
You can also use Garble at the same time. | 1 040 |
| 13 | کاری که « وایب کدینگ » با مهندسی نرمافزار کرد ، عمو جانی با هیچکس نکرد ! | 897 |
| 14 | Offsec trained ai model
Soon ... | 1 037 |
| 15 | Soon ... 🔥🔥🔥 | 4 |
| 16 | Binary-level obfuscation or source-code-level obfuscation — which one is better?
In my opinion, the answer is definitely source-code-level obfuscation.
Why? Because when you work at the source-code level, you have much more freedom and control over the transformations you can apply. You can manipulate the logic, control flow, data structures, and virtually every aspect of the code. more importantly, choosing source-level obfuscation doesn’t prevent you from adding additional binary-level protection later. You can still preserve the option to add multiple layers of binary obfuscation and protection on top of it.
The video you’re watching is a demo of a tool I wrote long before the rise of AI. I used this tool to obfuscate and harden all of the challenges published before. | 995 |
| 17 | در صورت حل این چالش، کد منبع پروژه رو تو گیت هاب قرار میدم.
زمان بندی هم نداره ، از روز انتشار تا هر موقعی که تونستید حل کنید | 916 |
| 18 | سالهای دور یک ابزار نوشته بودم که کد ++C تحویل میگرفت و کد مبهم سازی شده به همراه یک سری قابلیت ها مثل Virtualization, Control-Flow Obfuscation و ... روی سورس کد اعمال میکرد و کد مبهم شده رو برای کامپایل تحویل میداد ( رسما" یه پارسر برای زبان ++C بود که بدون AI دچار جراحت شده بودم واسه نوشتن اون ! )
برای چالش آخر از اون برنامه استفاده کردم ؛ تکنیک ها عین قبلی هستش فقط یک سری لایه های اضافه بهش داده شده ؛ برای علاقه مندان و متخصصین در حوزه مهندسی معکوس و حتی تحلیل بدافزار میتونه آموخته های زیادی به همراه داشته باشه.
شاید بگید این همه چالش میذاری که چی ! ولی هدف دارم که بعدش خواهم گفت.
هدف : پیدا کردن نام کاربری و شماره سریال صحیح | 1 105 |
| 19 | الوعده وفا ؛ با توجه به اینکه چالش توسط آقای Babak Mahmoodizadeh حل شد و بنا بود در صورت حل مساله سورس کد اون رو در گیتهاب منتشر کنم ؛ میتونید کد چالش رو مطالعه کنید و " یکی " از روشهای محافظت از کد رو یاد بگیرید.
پ.ن : در هیچکدام از بخش های تولید کد از AI استفاده نشده و توصیه میکنم به عنوان کسی که حدود 20 سال در حوزه امنیت تجربه داره سراغ وایب چی چی های مسخره نرید ، هدف من از اینکار و انتشار سورس کد یاد دادن مبحث به صورت غیرمستقیم هستش وگرنه متاسفانه الان همه برای خودشون یه استارت آپ مبتنی بر AI دارن !
https://github.com/NIKJOO/Freedom-CTF | 909 |
| 20 | ◀️ فایل چالش | 258 |
