Scott Noone @analyzev
Engineering Partner at OSR community.osr.com Manchester, NH Joined August 2010-
Tweets332
-
Followers873
-
Following114
-
Likes528
Has anyone else tried to decipher WinDbg's rdmsr/wrmsr syntax for ARM64? I *think* I have it figured out would gladly take a second opinion on what exactly KdpEncodeMsrAccess wants... community.osr.com/t/how-to-retri…
If you rely on Driver Verifier beware that it's not working as expected on Windows 11: osr.com/blog/2024/05/0…
WinDbg session is getting real: .prompt_allow +reg .asm no_code_bytes
Exploiting the NT Kernel in 24H2: New Bugs in Old Code & Side Channels Against KASLR by @gabe_k exploits.forsale/24h2-nt-exploi…
Anyone have any kernel crash dumps they want me to analyze in WinDbg? I'm working on updates for our next Kernel Debugging seminar and could use some new real world case studies (because ofc all bugs in my code are for demonstration purposes only 😂) osr.com/seminars/kerne…
So @j00ru published two posts on Windows Registry; given that there were a lot of fixes in Windows Registry in recent months I expect these to be fun ;) googleprojectzero.blogspot.com/2024/04/the-wi… googleprojectzero.blogspot.com/2024/04/the-wi…
If you like memory corruption, low-level internals and building custom decompilers to analyse novel exploits check out the write-up here: googleprojectzero.blogspot.com/2023/10/an-ana…
ProcMon 3.93 supports configurable minifilter altitudes. This is great for teams that have to support minifilters! Thanks @markrussinovich!
I took a tilt at solving LRPC client provenance - specifically the problem of parent correlation evasion via RPC-based indirect process creation. But ended up taking on a telemetry trustworthiness side quest… elastic.co/security-labs/…
I'm super proud of this 🚀
This is a pretty neat way to detect legacy NtCreateProcess calls that are generally abused for attacks like Process Doppelganging or Herpaderping.
This is a pretty neat way to detect legacy NtCreateProcess calls that are generally abused for attacks like Process Doppelganging or Herpaderping.
Abortion is a fundamental right for all women. It must be protected. I wish to express my solidarity with the women whose liberties are being undermined by the Supreme Court of the United States.
I took the past several days to do a write-up on my methodology in respect to identifying how a new change to KUSER_SHARED_DATA in Windows 11 Insider Preview was implemented. tl;dr looks like 0xfffff78000000000 is now read-only + a new randomized R/W view. connormcgarr.github.io/kuser-shared-d…
OSR's File System Minifilter and WDF Seminar Schedule - mailchi.mp/osr/osrs-file-…
Most important lesson learned this week: never trust someone with a WinDbg icon as their profile pic
The NTFS :$I30:$Bitmap bug found by @jonasLyk is super weird and annoying...FIFY: osr.com/blog/2021/01/2… (source + binaries github.com/OSRDrivers/i30…)
I've published a blog post on improving the Windows AMD64 memset implementation: msrc-blog.microsoft.com/2021/01/11/bui… cc @trav_downs
Windows Kernel cng.sys pool-based buffer overflow in IOCTL 0x390400 bugs.chromium.org/p/project-zero…
The Sept-Oct 2020 issue of The NT Insider is now available! - mailchi.mp/osr/dp3ddrrqgc
Waiting for the write *might* get you better app compat. Apps do stupid stuff like “open for write but never actually write” all the time.
Waiting for the write *might* get you better app compat. Apps do stupid stuff like “open for write but never actually write” all the time.

Tim Misiak @timmisiak
8K Followers 280 Following OS/systems engineer. Worked on WinDbg for a while. I write about low level tech sometimes. On bluesky: @timdbg.com On mastodon/fediverse: @[email protected]
Alex Ionescu @aionescu
47K Followers 2K Following Chief Technical Innovation Officer @crowdstrike. Windows Internals author and trainer. He/Him. RTs are not endorsements, opinions are my own.
Ivan Rouzanov @ivanrouzanov
2K Followers 1K Following Debug Engineer. Windows, drivers and all things kernel mode. I express my views, not my employer's. My views are my own and just my personal opinions.
David Weston (DWIZZZL... @dwizzzleMSFT
25K Followers 2K Following Corporate Vice President, OS Security and Enterprise @Microsoft
Joxean Koret (@joxean... @matalaz
8K Followers 4K Following سمووحخ ̷̴̐ خ ̷̴̐ خ ̷̴̐ خ امارتيخ ̷̴̐ خ 巴斯克恐怖 జ్ఞffective.Power لُلُصّبُلُلصّبُررً ॣ ॣh ॣ ॣ 冗జ بٍٍٍٍََُُُِّّّْرٍٍٍٍََُُِِّّّْآٍٍٍَُّ🦠بٍٍٍٍََُُُِّّّْرٍٍٍٍََُُِ
mdowd @mdowd
32K Followers 747 Following Internet Hacker. Founder of @vigilant_labs. Previously, co-founder of Azimuth Security (now L3Harris Trenchant)
Gabriel Landau @GabrielLandau
4K Followers 707 Following Tech Lead @ Elastic Security. Thoughts are my own. Also @[email protected] & @gabriellandau.bsky.social
Richard Johnson @richinseattle
18K Followers 3K Following Computer Security, Reverse Engineering, and Fuzzing; Training & Publications @ https://t.co/mloVP6rPB7; hacking the planet since 1995; Undercurrents BOFH
badidea 🪐 @0xabad1dea
30K Followers 629 Following Infosec sorceress • mad ethicist • she/her • queer • 厄 • I’m not trans, I just agree with the lifestyle.
Patsy Wyman @PatsyWyman7165
21 Followers 2K Following
timlake @timlake252160
0 Followers 2K Following
Ojaswi Kumar Mishra�... @0xojaxwi
73 Followers 2K Following Old-school Malware & Offensive Security REsearcher | ⚡Kernel Pwner⚡
Arpit Mathur @SixFingure
37 Followers 910 Following Don't expect me to do anything for this world now!
Marko Mladenovic @bugdigger
147 Followers 754 Following Game hacking, Windows Internals, Reverse Engineering, Hypervisors, (De)Obfuscation, Malware analysis, 0days
E11ie @P0int3rNu11
203 Followers 5K Following PlayStation 🎮| GT7🏁🏎️💨| The Last of Us💔🫂| God of War🪓💪🧔♂️| Days Gone🏍️🧟 | GTA Online💲🚗🚓...
Jonathan Malai @sncuvissl
8 Followers 275 Following
MirabelleLewis @3dBe0CCW4Ape9
79 Followers 7K Following
GameVandal @g4m3v4nd4l
0 Followers 110 Following I sell cheats. You win games. Everyone’s happy (except your opponents).
Adrien @chohco0A
2 Followers 61 Following
Patrick Sacchet @pjsacchet
0 Followers 255 Following
Pedro Justo @itanium_guy
499 Followers 156 Following 🇵🇹 https://t.co/aT6qKA7gVz https://t.co/Ery7KXM3Dh
SSssssSsssSsssss8888S... @Ss8S8sss88sss
1 Followers 206 Following
Tomer Eizenberg @EizenbergT47800
6 Followers 328 Following
ふなたひさえ @funatahisa11331
59 Followers 3K Following
dexter @dexter79331247
0 Followers 2K Following
nanjin002 @nanjin00272827
21 Followers 4K Following
Daniel Sokoler @DanielSokoler
1 Followers 387 Following
Saulius Krasuckas @sskras
855 Followers 2K Following I might get pro-trump and pro-so-called-conspiracies at frequent times so you might get annoyed by that. Otherwise I like *NIX, VMS + lower levels of the tech.
d1rkmtr @d1rkmtr
8K Followers 464 Following
Dor @Dor00tkit
374 Followers 661 Following
friendzj @friendzj
3 Followers 104 Following windows kernel developer and Researcher,Focus on file system and artificial intelligence。
rimonyonatan @rimonchello
3 Followers 134 Following
Gerson @Gerson62009665
20 Followers 398 Following
Vivek @0xda0xde
39 Followers 644 Following
Data Masked @_data_masked
26 Followers 264 Following Not a bot. I'm just here so I don't get fined. Primarily a lurker.
Gala @Gala14055947
3 Followers 74 Following
Singularity Fellas �... @insinu8or
2K Followers 8K Following Cats Division. Retweets are just someone's opinions for you to take a look, I don't necessarily agree. Likes are not endorsements.
Laércio Mesquita @lnmesquita_
4 Followers 250 Following
Asukiko @asukiko_f
19 Followers 1K Following Seek and destroy threats | I will find your malware and take down it | DM for Study together | I do not use Twitter so much | him, his | @Intelis_ABIN Agent/SEC
Muntea Andrei @muntea_andrei
2 Followers 193 Following
Sokratis @sokratissz
64 Followers 1K Following
Damian Wilson @scampbird
446 Followers 1K Following The programmer, not the singer. Views are my own. Tweets older than 3 months deleted. Same account name on IG/Youtube.
Windy Bug @0xwindybug
355 Followers 2K Following
Theaus @Theaus167224
18 Followers 2K Following
Kristie @brownkristie15
247 Followers 3K Following
Marianne @j_marianne3
280 Followers 3K Following
David @David2173245707
19 Followers 110 Following
Tera @freeman_tera27
292 Followers 3K Following
Yarden Shafir @yarden_shafir
24K Followers 309 Following A circus artist with a visual studio license
chompie @chompie1337
83K Followers 1K Following hacker, weird machine mechanic, X-Force Offensive Research (XOR)
Satoshi Tanda @standa_t
8K Followers 395 Following Software security engineer and trainer https://t.co/tenaquooTc
Tavis Ormandy @taviso
130K Followers 631 Following Vulnerability researcher at Google. This is a personal stream, opinions expressed are mine. I'm also @[email protected]
Andrea Allievi @aall86
5K Followers 374 Following Currently Senior Windows Core OS Engineer, Windows Internals Enthusiast and Book author, tennis lover, currently working for MS. Opinions and tweets are my own.
Gabriel Landau @GabrielLandau
4K Followers 707 Following Tech Lead @ Elastic Security. Thoughts are my own. Also @[email protected] & @gabriellandau.bsky.social
Maddie Stone @maddiestone
61K Followers 804 Following Security Researcher. Previously Google Project Zero and TAG | 0days all day. Love all things bytes, assembly, and glitter. she/her.
h0mbre @h0mbre_
15K Followers 641 Following # Exploit Reliability Engineer # Developing a full-system snapshot fuzzer: https://t.co/mfVXhwoGYD # Avi: https://t.co/3fsQfVprCf
Andrew Richards @ARichardMSFT
829 Followers 240 Following Principal Developer in Windows Reliability - !analyze, Symbol Protocol, Sysinternals ProcDump. Co-host Channel 9 Defrag Tools (@defragtools) and Inside Show.
Falco Girgis @falco_girgis
9K Followers 1K Following Sega Dreamcast developer on a quest to correct the timeline of video gaming history. Working on the modern, open-source indie DC SDK and library OS, KallistiOS.
Eric Fradella @darcag3nt
301 Followers 184 Following Embedded Systems Developer | Dreamcast / GameCube dev enthusiast | KallistiOS Team | Owner - https://t.co/r1m62vbOT4
Jeff’s Retro Gaming @RetroJeff83
3K Followers 916 Following Console and handheld repair, restoration and modding services. Reach out via DM or on by website linked below with any inquiries!
Longhorn @never_released
14K Followers 143 Following Kernel/hypervisor engineer @awscloud EC2. Hobby @checkra1n. Mastodon: https://t.co/DsXP8PFgL0 Bluesky: https://t.co/dAOfFSSqY4
Pedro Justo @itanium_guy
499 Followers 156 Following 🇵🇹 https://t.co/aT6qKA7gVz https://t.co/Ery7KXM3Dh
Cobalt Strike @_CobaltStrike
5K Followers 32 Following Official account for Cobalt Strike. Benchmark red teaming tool known for its flexibility and powerful user community. Follow for new releases and other updates.
Dennis Elser @sdkboi
1K Followers 387 Following
WalkingCat @_h0x0d_
11K Followers 477 Following The Cat Walking In The Night https://t.co/8WsGx4qYXl https://t.co/6aHUJcjvXY https://t.co/W7KHy1JCl0
Asahi Lina / 朝日�... @LinaAsahi
35K Followers 195 Following Hello everyone, Asahi Lina here! I'm a developer VTuber! EN/日本語|🎨 #AsahiLinArt|Model @NananoNanase|Design @shiranui_illust|PFP @7783__|My gf: @CyanNyan6 🩵
Ben Cox (EOL @benjojo... @Benjojo12
9K Followers 253 Following Hope you never notice the outages I cause. Knows where the RFC2616 bodies are buried. @recursecenter SP'2 18 Also @[email protected]
Phillip Koskinas @deteccphilippe
8K Followers 111 Following fashion over-enthusiast @johnvarvatos, frontman for @gaxmamble, and head of anti-cheat @riotgames, formerly @amazongames
ZwClose @zwclose
1K Followers 58 Following
lander @landaire
3K Followers 450 Following working in security. tweets directly reflect the opinions of @carrot_c4k3
Microarch Club @MicroarchClub
573 Followers 1 Following The art, science, and history of processor design. Hosted by @hasheddan.
Grant Sanderson @3blue1brown
411K Followers 362 Following Pi creature caretaker. Contact/faq: https://t.co/brZwdQfdif
Topvint @topvint
3K Followers 1K Following No drama, just refurbishing and modding game consoles. Check my online shop!
Jon Bruner @JonBruner
32K Followers 2K Following Turning atoms into bits at @lumafield. Join our team! https://t.co/8braYCl908
Vector 35 @vector35
10K Followers 2K Following Makers of the Binary Ninja - Reverse Engineering Platform. https://t.co/opkys50srq Also posting at https://t.co/2HEfgOtSSR
Phoronix @phoronix
61K Followers 119 Following Founded by @MichaelLarabel in 2004, Phoronix is the largest #opensource news, #Linux hardware reviews & Linux PC/server/HPC performance benchmark site.
Cory Doctorow NONCONS... @doctorow
472K Followers 3K Following New book: ENSHITTIFICATION: WHY EVERYTHING SUDDENLY GOT WORSE AND WHAT TO DO ABOUT IT https://t.co/YtuuAC6GPZ @[email protected]
3DO, PS1 & Atari Will @ste_mega
10K Followers 9K Following 🎮 Real hardware. Obscure systems. Bad takes. 📼 Last of the 3DO Fanboys. “A misunderstood genius of poor purchasing decisions.”
Adam @helpcomputer0
19K Followers 978 Following Pixel artist. Prints: https://t.co/5pesWtsGAG https://t.co/2TYwD5vAze
Ron Filipkowski @RonFilipkowski
1.0M Followers 2K Following Editor-in Chief https://t.co/HLS0hEHY1C, Co-host Uncovered, Attorney, Marine, Former Federal and State Prosecutor, Republican Party Insane Asylum Escapee
debug @0xdbug
774 Followers 779 Following Security engineer, developer and hobbyist reverse engineer in that order. Opinions/rants are all mine and not my employer's.
Mudge @dotMudge
63K Followers 337 Following Make a dent in the universe. Find something that needs improvement: go there and fix things. If not you, then who? {he/they}
David Kean @davkean
12K Followers 679 Following I work on performance on Visual Studio @ Microsoft. Previously .NET. He/Him.
matt godbolt is mostl... @mattgodbolt
15K Followers 2K Following Husband, father, coder, sometime verb, real person. Fond of old hardware. Co-host @twoscp. #BlackLivesMatter. @matt.godbolt.org on bsky He/him
sixtyvividtails @sixtyvividtails
3K Followers 393 Following Currently working as an independent GUID merchant. Fully licensed. I acquire, produce, and sell high-quality GUIDs.
Davide Italiano @davidecci
2K Followers 65 Following
Dethrace Labs @dethrace_labs
1K Followers 95 Following Reverse engineering the 1997 game Carmageddon (known internally as "Dethrace")
derek guy @dieworkwear
1.4M Followers 958 Following Menswear writer. Editor at @putthison. Creator of @RLGoesHard. Bylines at The New York Times, The Financial Times, Politico, Esquire, and Mr. Porter
Aric Toler @AricToler
133K Followers 1K Following @nytimes Visual Investigations Previously @bellingcat [email protected] https://t.co/aHPY73i935 Signal/Telegram/WhatsApp: +1 913-209-0215
Judd Legum @JuddLegum
510K Followers 1K Following I write Popular Information, an independent newsletter dedicated to accountability journalism. | [email protected] | Signal/Text: 202-599-7124 | DMs open
John U @jdu2600
678 Followers 345 Following He/him. Security Research Engineer @preluderesearch. ex-@elasticseclabs ex-@CyberGovAu
Jacques Fortier @jacquesgt
2K Followers 144 Following Firmware, operating systems, and security at billion device scale, but mostly pictures of my cat. @[email protected]
John Scott-Railton @jsrailton
162K Followers 2K Following Chasing digital badness. Sr. Researcher @citizenlab @UofT @munkschool. Fmr.Ed. @SecPlanner. Tweets mine. Other platforms @jsrailton too.
Kelvin Chan @KelvinMsft
984 Followers 10 Following @Microsoft Windows Kernel & Hyper-V Hypervisor Engineer | make the world a little bit more secure