vx-underground Profile picture
Nov 16 3 tweets 1 min read Read on X
Tbh I think if someone fr wants to learn malware development you shouldn't even begin studying malware techniques

You should focus on things that interact with the OS, like file creation (and all the silly quirks of it on Windows), working with the registry, file system enumeration, basic networking stuff (WinHTTP vs WinInet vs WinSocks vs IpHelper).

Having a good understanding of these will make life a lot easier

Then when you feel really really comfortable and do silly stuff like that, then slowly introduce some malware stuff because a lot of malware stuff is just abusing the concepts described above

Also probably explore the Windows API and all the weird shit inside of it that isn't documented well. I also recommend reviewing ReactOS source code to get an understanding of what's going on under the hood

ReactOS isn't 1-1, but it's close enough
Windows unironically has a fuckin bazillion different ways to make files and work with them. Even understanding all of these different ways can be super beneficial
If I had the time, energy patience, and anime, i could make like a fucking 2 hour long documentary on YouTube just discussing file creation on Windows (from the user mode side)

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with vx-underground

vx-underground Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @vxunderground

Aug 1
From the Google Dork-able ChatGPT conversations, someone noted the discovery of a person who believes they're in an intimate and/or sexual relationship with ChatGPT.

It is a very long read. It isn't someone being ironic. It is one of the strangest thing I've ever read. Image
Image
Image
Image
Yeah, I'm killing myself tonight. Image
Burn all AI to the ground. This man's brain is COOKED Image
Image
Read 4 tweets
Dec 7, 2022
Today it was reported the United States has allocated $44,000,000 for their annual cyber defense budget.

They have successfully allocated enough funding to purchase VirusTotal Enterprise, a few RecordedFuture licenses, and have installed CarbonBlack on 4 computers
6 months of VirusTotal Enterprise*
haha just teasing RecordedFuture ily

please don't take away our Triage account
Read 4 tweets
Sep 16, 2022
Uber is currently responding to a "cybersecurity incident".
Update: A Threat Actor claims to have completely compromised Uber - they have posted screenshots of their AWS instance, HackerOne administration panel, and more.

They are openly taunting and mocking @Uber. ImageImageImageImage
@Uber They disclosed Uber's financial data

🧐 Image
Read 5 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(