BOLT is a static analysis tool, part of LLVM compiler infrastructure, used to verify that compiler security hardening options have been applied on a binary.
Thanks to @OSTIFofficial we've worked since November 2025 to improve it. Check our progress here:
blog.quarkslab.com/extending-llvm…
From prompt 😃to pwned 😢:
Implementing an LLM in your org? Useful.
Trusting its output? That's how a low-priv user became admin.
Ship the feature, don't extend it your trust.
blog.quarkslab.com/from-prompt-to…
Practical Android Software Protection in the Wild: An Appetizer
In which @Farenain analyzes 2.5 million Android apps to identify and classify the obfuscators, packers and code protectors they use:
blog.quarkslab.com/practical-andr…
What happens when reverse engineers spend weeks digging into a Scala 3 codebase?
🔍 From code review to fuzzing, our assessment helped strengthen Scala's security .
The results of our audit, conducted in collaboration with @OSTIFofficial, are here:
blog.quarkslab.com/scala-security…
Did you hear about Optical Line Terminals? ISPs rely on them to build their service networks, but what if they're vulnerable?
Here @Coiffeur0x90 shows how attackers could compromise entire ISPs by exploiting them and cloud-based fleet management software
blog.quarkslab.com/how-olts-may-h…
A hands-on look at Microsoft’s Independent Guest Virtual Machine (IGVM) format inside OpenHCL’s `openhcl.bin`.
We unpack the fixed header, variable headers, data layout, and how IGVM measurement supports Confidential Computing with SEV-SNP and TDX.
🔗blog.quarkslab.com/the-igvm-file-…
Paramiko is a pure-Python implementation of SSHv2. Recently, we worked with the Paramiko team on a security audit sponsored by @OSTIFofficial 🙏
Read a summary of our findings and find the full report here:
blog.quarkslab.com/paramiko-secur…
My new blog post is released. It explains in detail how applications (App Registrations, Service Principals, MI) and their permissions really work, why they can introduce several subtle paths for privilege escalation, and presents my open-source tool designed to uncover them.
Do you know how Entra ID applications work?
What about the security mess they can bring and what they can quietly break?
New blog post on Entra ID application permissions, the audit nightmare they create, and QAZPT, our OSS tool built to make sense of it:
blog.quarkslab.com/auditing-appli…
Do you know how Entra ID applications work?
What about the security mess they can bring and what they can quietly break?
New blog post on Entra ID application permissions, the audit nightmare they create, and QAZPT, our OSS tool built to make sense of it:
blog.quarkslab.com/auditing-appli…
Obfuscation vs The Optimizer: A Battle in LLVM Middle End.
@yates82 shows us how the continuous improvement of the LLVM optimizer defeats naive code obfuscation, and how the obfuscator can fight back.
An eternal fight in which all victories are ephemeral
blog.quarkslab.com/obfuscation-vs…
🤔Ever wondered how your favorite tools work under the hood? During our work on SightHouse, we dug into BSIM, Ghidra's Binary function SIMilarity engine.
Many tools have been built around it, yet its internals remained undocumented. Until now 👇
blog.quarkslab.com/bsim-explained…
🚗 We traced a car’s life from China to Poland.
By analyzing a BYD Telematic Control Unit, Romain Marchand reconstructed its journey and identified a real-world event from GPS logs alone.
Embedded forensics + OSINT = real stories hidden in data.
👉 blog.quarkslab.com/tearing-down-a…
Recently @quarkslab published a solution of a CTF using TritonDSE and QBDI where they analyzed a VM protected binary, and I thought "Shit, I want to analyze something too...". And this weekend I did an analysis of another crackme with a custom VM but this time using Triton! 🧵
After @Coiffeur0x90 found 3 LPEs in Intego antivirus for macOS, @kaluche_ had to check the Windows version too.
Spoiler: it was vulnerable.
Here's the full write up of a symlink attack to achieve Local Privilege Escalation👇
blog.quarkslab.com/milking-the-la…
Tired of reversing the same libc for the 100th time? 👀
Meet SightHouse, our open-source tool that automatically detects third-party library functions in binaries.
High-confidence function mapping. Works with any disassembler. By @Mad5quirrel & Sami.
🔗 blog.quarkslab.com/sighthouse-aut…
The dragon has a VM. Of course it does. Our latest blog walks through the analysis of a complex C++ binary hiding behind a virtual machine, themed as a classic RPG fight. QBDI & TritonDSE are your weapons of choice. The dragon doesn't stand a chance. 🐉
blog.quarkslab.com/qbdi-vs-triton…
Rule 1️⃣ : "In WAF we (should not) trust"
Your WAF is doing its best. That's just not enough 😮💨
A deep dive into Web Application Firewall bypass techniques, discovering why blocked ⛔ doesn't always mean safe.
blog.quarkslab.com/in-waf-we-shou…
"Intego X9: Never trust my updates"
Read @Coiffeur0x90's research showing how XPC interprocess communications and the update mechanism of the Intego antivirus for MacOS can be abused for local privilege escalation.
blog.quarkslab.com/intego_lpe_mac…
"How does it even work?"
The question that keeps hackers' hearts pumping, blood pressure rising, and curiosity growing.
This is @virtualabs's reverse engineering journey into a cheap smartwatch that measures at least one of those.
blog.quarkslab.com/nerd-life-week…
SPONSOR
📣 Today, we are very happy to announce the @quarkslab Gold level sponsoring 😍
📄 @quarkslab provides to companies Security Audit capabilities, Consulting expertise powered by its cutting edge R&D and Qshield, its comprehensive security suite
1/2
45K Followers 3K FollowingChoose disfavour where obedience does not bring honour.
I do math. And was once asked by R. Morris Sr. : "For whom?"
@[email protected]
62K Followers 796 FollowingSecurity Researcher. Previously Google Project Zero and TAG | 0days all day. Love all things bytes, assembly, and glitter. she/her.
47K Followers 2K FollowingChief Technical Innovation Officer @crowdstrike. Windows Internals author and trainer. He/Him. RTs are not endorsements, opinions are my own.
28K Followers 628 FollowingWeb hacker and Burp Suite Pro trainer
Refer to https://t.co/D5tRH7U2hg for trainings
Follow @MasteringBurp for free tips and tricks
14K Followers 562 FollowingAssociation loi 1901 depuis 1998 sur les logiciels libres.
☁️: bluesky: @lealinux.org
🐘: [email protected]
📩: bureau@
(Pas de support technique en DM)
48K Followers 2K FollowingMusic, cybersecurity, open source and AI • Author of bettercap, pwnagotchi, opensnitch, bleah, legba and a few other things.
Chief Architect @ 🥷
33K Followers 1K Following意志 / mobile research @ ▓▓▓▓▓ / Team 501 / ex IBM Capability Lead & FireEye TORE / I rewrite pointers and read memory / AI Psychoanalyst / Teaching @CalypsoLabs
28 Followers 964 Followingnext-frontier technologies + global knowledge systems + trust infrastructures. finally, service marketplaces where everyone prospers.
41 Followers 1K FollowingTech superhero 🦸♂️ Solving problems and making magic happen 💻️ 20+ years in IT management, and still having fun! 💪️ #ITManagement | #ManagedServiceProvider
84K Followers 54 FollowingCompte officiel de l'Agence nationale de la sécurité des systèmes d'information (ANSSI) | Retrouvez les alertes de #cybersécurité sur le compte @CERT_FR
58K Followers 40 FollowingCentre gouvernemental de veille, d'alerte et de réponse aux attaques informatiques.
Pour toute question : [email protected] ou par téléphone au 3218
@ANSSI_FR
2K Followers 766 FollowingEuropean Cyber Cup 🏆 | 1ère compétition d'eSport dédiée au hacking éthique, pendant le Forum INCYBER @INCYBER_Eu | 📅 9-11 mars 2027
2K Followers 1 FollowingA dynamic binary analysis library. Build your own program analysis tools, automate your reverse engineering, perform software verification or just emulate code.