Alexander H.
2025-06-20

github.com/alexander-hanel/pwi

For anyone else tired of having to start a VM to download a file.

2025-04-11
2025-04-11

@cxiao @pinkflawd Ha! Decompiler output is ugly compared to the esthetic simplicity of assembly.

Alexander H. boosted:
williballenthinwilliballenthin
2024-09-23

Unicorn Engine (CPU emulator) v2.1.0 released with lots of goodies. I’m particularly interested in the

memory snapshots/CoW support, to enable approximate emulation of all code paths, like we do in FLOSS.

github.com/unicorn-engine/unic

Alexander H. boosted:
2024-01-10

We at CrowdStrike are looking for a highly technical colleague that helps me study threats to the cloud! We are a remote first company, have a great data set, and need additional headcount. You would work with me directly in the Technical Analysis Cell. Together we would be the first to analyze cloud activity logs to discover and document new techniques such as persistence via identity federation (cisa.gov/news-events/cybersecu).
crowdstrike.wd5.myworkdayjobs.
If you have any questions, feel free to reach out to me via direct message. Note that I’m not the hiring manager.
We had to specify a region for our hiring portal which is why it states USA-/Canada-Remote. While this would be ideal to increase our window of coverage, we will consider candidates from all regions where we can hire. I myself am based in Europe.
#cloudsecurity #cloud #threatintel #hiring #aws #azure #gcp #FediHire #fedihired #remotework #remote

Are you not interested in analyzing/documenting cloud-conscious threat actor activities but would rather help catch them via cloud honeypots and search/reproduce vulnerabilities at cloud service providers? Then this position for a colleague in the ART team might be something for you: crowdstrike.wd5.myworkdayjobs.

2023-12-29

A while back I was researching A5/1 encryption (used in GSM) and I stumbled upon its fascinating history. I wrote about some of the notable points here github.com/alexander-hanel/asm

2023-12-15

@r3c0nst awesome job. This is some great content.

Alexander H. boosted:
williballenthinwilliballenthin
2023-12-14

“FLOSS for Gophers and Crabs: Extracting Strings from Go and Rust Executables” mandiant.com/resources/blog/ex

Alexander H. boosted:
2023-12-13

Viewing Microsoft’s technical specifications in IDA? That’s possible with Alexander Hanel’s Plugin – msdocviewer. Read our new #PluginFocus article and learn more about this simple but helpful tool 🌐 hex-rays.com/blog/plugin-focus

#IDAPython

Plugin Focus -msdocviewer
Alexander H. boosted:
Jesko Hüttenhainrattle@infosec.exchange
2023-11-12

As promised, here are my #BinaryRefinery solutions of #FlareOn10. Didn't quite refine them all, but there might be a nugget or two if you like static analysis:

github.com/binref/refinery/blo

Alexander H. boosted:
2023-11-08

Newly released: recording of Daniel Plohmann's #VB2023 presentation on applied one-to-many code similarity analysis using MCRIT. Watch out for more VB2023 presentations being released on our YouTube channel in the coming days. youtube.com/watch?v=CMu1r5IhpY

Alexander H. boosted:
2023-11-01

Emily Gorcenski banned her phone from the bedroom and started reading again. “I started to take inventory of the hours I was losing. It was bad. I was worried I was wasting my life with bullshit I could not control and could do nothing about.” emilygorcenski.com/post/how-i-

Alexander H. boosted:
Dmytro Oleksiukd_olex
2023-10-24

My Hyper-V backdoor now fully supports Windows 11, both 21H2 and 22H2. All features and client program commands, including secure kernel related ones, works as expected 😀

github.com/Cr4sh/s6_pcie_micro

2023-10-23

msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA. github.com/alexander-hanel/msd

2023-10-21

@jimfl @cxiao the author’s book A Burglar’s Guide to the City is an excellent read. burglarsguide.com/

2023-10-16

@larsborn hahaha so basically same-same, but different.

2023-10-16

I’m on my last week of a 12 week paternity leave and was looking to get caught up on notable research/blogs/videos/code/etc of the past three months. What would you recommend checking out?

2023-09-28

@cyb3rkitties if you skip to the second paragraph I describe my approach to triaging a piece of malware. hooked-on-mnemonics.blogspot.c

Alexander H. boosted:
Christian Blichmann🇺🇦AdmVonSchneider@infosec.exchange
2023-09-25

In the spirit of "this talk could've been a tweet", I just pushed a button:

#BinDiff is now open source.

- This is a snapshot release, no major new functionality
- Release binaries will follow later today or tomorrow
- This is my 20% and I won't we able to act on PRs until end of Q4 (OOO traveling)

Thanks everyone for making this possible!

Shout out to @HalvarFlake, ObfuscaTHOR, Nils, Tora,
@shanehuntley, @erocarrera, 0xfffffffe

Happy diffing!

github.com/google/bindiff/rele

2023-09-19

For anyone interested in barbell exercises (squat, deadlift, etc), I created a gist of my warmup routine. The stretches are also useful for countering stiffness from sitting. I do some of these throughout the day when I’m working. gist.github.com/alexander-hane

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst