@hau_zy Profile picture

aaron hau

@hau_zy

🤓 nerd 🤷‍♂️ joined twitter cos everyone seems to be sharing stuff here #FOMO

Joined May 2020
Similar User
AsiaCCS photo

@ASIACCS2024

Javier C. Cano photo

@ccanojavi

Adepu Sridhar photo

@sridhar933

SCCS photo

@SCCS_UniSurrey

Ioana Boureanu photo

@icboureanu

John Doe photo

@InfoSecJohnDoe

cyb3rmeerk4t photo

@cyb3rmeerk4t

Azhar Desai photo

@azhrdesai

Mohit Vadehra photo

@mvdfir

aaron hau Reposted

“Break into the world of vulnerability research... and become a zero-day hunter.” I have a new book with @nostarch! Behind the curtain of zero-day research, there are fundamental building blocks you can learn. In early access now and out in Spring 2025! nostarch.com/zero-day


aaron hau Reposted

If you spend too much time with people who don't have any ambitions, you'll soon lack the fire to excel.


aaron hau Reposted

BLOG POST: We've been investigating the #Quad7 7777 botnet for a while, we thought it was time to share some of our findings. Includes discovery of the linked 63256 botnet which targets #ASUS routers. team-cymru.com/post/botnet-77… h/t @Gi7w0rm


aaron hau Reposted

#100DaysOfYara Since everyone talks about detection, I want to share some tips about efficiency & performance with YARA, especially if you're dealing with tons of rules and files like us First up: Don't use modules if you don't have to A few examples: - no need to import…


aaron hau Reposted

"...thinking clearly is thinking independently."

Tweet Image 1

aaron hau Reposted

Caring about whoami? Despite common belief, it doesn't use GetUserNameEx() unless you specify /UPN or /FQDN param! Whoami calls OpenProcessToken() to get process token, then GetTokenInformation() to get SID, and finally LookupAccountSid() to get username. You have been warned ;)

Tweet Image 1

aaron hau Reposted

I wrote a lot about the people I call "shapers" in my book Principles: Life & Work. I use the word to mean someone who comes up with unique and valuable visions and builds them out beautifully, typically over the doubts of others. Shapers get both the big picture and the details…

Tweet Image 1

aaron hau Reposted

🧵 (1/) Bypassing IDS DCSync Signature for #secretsdump I’ve been asked lately to bypass a private IDS rule for #impacket’s DCSync operation and I’ve immediately remembered this Charlie’s question ⬇️

If you wondered why you need a CIFS SPN for secretsdump, and an LDAP SPN for Mimikatz, know one thing, you're not alone 🥲 If you do know why, halp, pleaz ❤️

Tweet Image 1
Tweet Image 2


I outsmarted this AI chatbot in Immersive Labs' prompt injection skills challenge! Can you? @immersivelabs #ai #cybersecurity prompting.ai.immersivelabs.com


aaron hau Reposted

Publishing today a position paper on Generative AI - a lot of promise, but many challenges. Available as CERT-EU Security Guidance 23-002 - cert.europa.eu/static/securit…


aaron hau Reposted

Check out our latest blog by Aaron (Zhongyuan) Hau where he discusses how an advisory can take advantage of normal everyday cyber hygiene issues to compromise the whole network. threatspike.com/blogs/aad


aaron hau Reposted

Remember the large #GoogleAd spike earlier in the year deploying malware? Our team did a write-up on the malware that was delivered at the last stage. We couldn't identify any public family names with this hVNC malware so we are calling it #LOBSHOT 🏸

#ElasticSecurityLabs highlights a new #Malware family we call LOBSHOT, deployed as part of a Google adwords malvertising campaign. Read more about this financially-motivated threat here: go.es.io/41FRzxu



And so it begins...

Aaaaaaaand prompt injection in VT’s new feature. Puppies can’t be malicious. (Not the creator, sent to me) virustotal.com/gui/file/264be…

Tweet Image 1


aaron hau Reposted

Introducing the Living Off The Land Drivers (LOLDrivers) project, a crucial resource that consolidates vulnerable and malicious drivers in one place to streamline research and analysis. loldrivers.io LOLDrivers enhances awareness of driver-related security risks and…


Loading...

Something went wrong.


Something went wrong.