@IAMMOLESTED@momo5502 A Windows emulator needs real DLLs for it to be as compatible as possible. "close enough" as in wine eventually isn't. Wine is a 30 years of app-specific hacks. I think that he is got a real shot here if he gave it more work. some early TH8 footage doesn't disprove that :/
Added initial support for GUIs in Brovan, my windows & linux emulator.
Now windows and linux hosts while emulating a PE file can render a Windows GUI. This is a demo of it running in WSL.
Definitely more to work on.
@momo5502 That's actually really cool, seeing it going from just an emulator for analysis to something that can one day run actual software safely is incredible. Keep going!
After months of work, I released Brovan, a user-mode binary emulator for PE, ELF, memory dumps, and unknown binaries. Built for reversing, analysis, and full control over execution. Check it out!
github.com/AdvDebug/Brovan#REversing #malware#malwareanalysis #csharp#emulator#RE
It was a pleasure to contribute as an author and create my reverse engineering challenge "Virtual Mind" for DeadSec CTF 2025. I hope you all enjoyed the event and had a great time solving it! see you in the next one.
Just solved the PicoCTF SaaS (Shellcode As a Service) challenge and made a writeup about it.
i made a medium account so i can cover the topics i wanna talk about. from reverse engineering to exploitation. check it!
medium.com/@AdvDebugy/pic…#CTF#CyberSecurity#PicoCTF#Hacking
Check out my #opensource tool "AntiCrack-DotNet" on #github!
It's an advanced tool to detect malicious actions like lookups, injection, debugging, hooks, etc. with reliable and strong detection that works with AOT, and can be built as a client-side AC.
github.com/AdvDebug/AntiC…
@LiveOverflow@steinerkelvin@alex8x8 yes, most people that make this kind of malware are just script kiddies that copy-paste code and if the browser encrypted the profiles (some give an option to do that but they have an insecure implementation) it will make it more complex and time consuming to get them from memory
@SecurityJon What kind of backdoor? I think this tweet is misleading, the binaries are open-source and it doesn't even run in the background and it only shows up when you press shift 5 times and you can close it by pressing the close button on the console (it never runs in the background)
@c3rb3ru5d3d53c it changes the Page Protection of the function DbgUiRemoteBreakin which are an API being called when a debugger uses DebugActiveProcess API, and then probably patch it so that this function can't be actually called (or similar). (Anti-Debugger Attaching)
2K Followers 2K FollowingMuslim web security artist 👨🎨, Pwn N00b 🤔 ACU🇨🇦 Graduated, Developing and breaking codes since 2020&Captin of @0xL4ugh and flagger @idekCTF. 💻
91K Followers 957 FollowingProgrammer, #malware analyst. Author of #PEbear, #PEsieve, #TinyTracer. Private account. All opinions expressed here are mine only (not of my employer etc)
2K Followers 2K FollowingMuslim web security artist 👨🎨, Pwn N00b 🤔 ACU🇨🇦 Graduated, Developing and breaking codes since 2020&Captin of @0xL4ugh and flagger @idekCTF. 💻
89K Followers 18 FollowingTrendAI Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.