YouTube video by Recon Conference
Recon 2025 - The Finer Details of LSA Credential Recovery
@reconmtl.bsky.social has uploaded the majority of the 2025 talks, including my talk on LSA. You can check it out at the below link if you'd like.
Thank you again to the organizers and everyone else who helps put on the conference. I look forward to coming back!
youtu.be/G2CfMWXLU1U?...
16.10.2025 15:34 — 👍 10 🔁 5 💬 0 📌 0
Interesting memory dump analysis in WinDbg. I think it's very useful not to show only the "golden path" to the solution!
10.10.2025 14:24 — 👍 0 🔁 1 💬 0 📌 0
To be honest, I can't believe I missed this. The !analyze -v command was already pointing to the driver as the cause, but I ignored it. I guess I'll have to double-check more carefully next time, but I'm satisfied with the analysis I've done. 😅
08.10.2025 01:29 — 👍 0 🔁 0 💬 0 📌 0
Of course the private symbols are not available, so the ETW traces might be difficult to read. Other than that, it collects relevant data though :-)
21.09.2025 10:01 — 👍 0 🔁 0 💬 0 📌 0
Anyone used the TSS Troubleshooting script from MSFT before? I saw an Escalation Engineer used it, so I'd thought it could be interesting to others as well. The use-case was troubleshooting LSASS high CPU on a DC... learn.microsoft.com/en-us/troubl...
21.09.2025 09:42 — 👍 1 🔁 0 💬 2 📌 0
Has anyone already ditched Twitter for Bluesky? I’m still more active on Twitter, but I’ve noticed some people have moved over to Bluesky.
13.09.2025 14:14 — 👍 4 🔁 0 💬 4 📌 1
Eww PowerShell.
12.09.2025 17:49 — 👍 0 🔁 0 💬 0 📌 0
Power IRP timeout in RAS SSTP causes Blue Screen 0x9F during sleep
We’ll first start with the !winde.infocommand, which tells us that this system is a Windows 10 version 19041 on an 8 core Intel machine…
New blog post of me analyzing a crash dump with the bugcheck 0x9F. Root cause was a power IRP timeout in RAS SSTP during a device removal. The post walks PnP locks, the stuck IRP, and more, including my thought process. Check it out here: medium.com/@Debugger/po...
12.09.2025 17:46 — 👍 3 🔁 1 💬 0 📌 1
Agreed. I still use Twitter though, but I've reduced my social media time a lot.
07.04.2025 09:04 — 👍 2 🔁 0 💬 0 📌 0
Yeah, same here :)
07.04.2025 08:16 — 👍 0 🔁 0 💬 0 📌 0
Is there anyone who completely ditched Twitter and now only uses Blue Sky? 😅
07.04.2025 08:10 — 👍 1 🔁 0 💬 3 📌 0
TextAnalysisTool.NET
TextAnalysisTool.NET: A program designed to excel at viewing, searching, and navigating large files quickly and efficiently.
For those that are doing a lot of log analysis. textanalysistool.github.io is a free open-source tool that I've been using to analyze ESXi, Citrix, MpLogs, Teams support logs, etc. It can be useful when you deal with those raw format logs.
15.01.2025 11:03 — 👍 0 🔁 0 💬 0 📌 0
Who uses WinDbg as well in their daily work?
09.01.2025 13:35 — 👍 0 🔁 0 💬 0 📌 0
- No more pizza with pineapple
07.01.2025 17:14 — 👍 1 🔁 0 💬 0 📌 0
GitHub - DebugPrivilege/InsightEngineering: Hardcore Debugging
Hardcore Debugging. Contribute to DebugPrivilege/InsightEngineering development by creating an account on GitHub.
Wishing everyone a Happy and Healthy 2025! 🎉- In case you missed it, I created a GitHub repository in 2024 covering Windows Debugging topics. It includes using tools like WinDbg to analyze memory dumps and more. If you're into Windows, check it out here: github.com/DebugPrivile...
31.12.2024 10:11 — 👍 7 🔁 1 💬 0 📌 0
Blijf bij. NOS
Volg ons voor al het laatste nieuws.
https://nos.nl/
computer security person. former helpdesk
ALT ACCOUNT OF @debugger.bsky.social FOR HARDCORE NERD RANTS AND WILD, RANDOM TANGENTS.
Running ➡ http://defendpoint.ca | http://edr-telemetry.com | https://edr-comparison.com/ | http://detectionstream.com | 🇬🇷🇨🇦
Cybersecurity Specialist, Public Speaker, Ex-Hacker.
https://marcushutchins.com
Bot combinator of RSS feeds of Dutch news sites ad.nl geenstijl.nl mediacourant.nl metronieuws.nl nos.nl nrc.nl nu.nl rtl.nl telegraaf.nl and volkskrant.nl
I'm Thee Sarcastic Warrior, Keeper of Secrets in MSR, Inquisitor of the CTO, Defender of Caturdays, Hugger of Trees and Hunter of Bots.
cybersecurity weather man. scanning the horizons for cloudy cyber. Expert at nothing except computer rubbish. Anti-ransomware since 2015.
- [REDACTED]’s husband
- Bear's dad
- Recovering sysadmin
- Microsoft MVP (PowerShell/Identity)
- Forever student
- Open-Source Toolmaker
- Whisk(e)y fan
- College football fan (Go Blue!)
- Stuff: https://dotdot.horse
The best of FT journalism, including breaking news and analysis.
https://www.ft.com
The users this account follows are verified FT staff or contributors.
MSFT, author of Advanced Windows Debugging and Advanced .NET Debugging, Principal Software Engineer leading the Sysinternals team. Opinions are my own.
OS/systems engineer, co-founder of Augmend. I used to work on WinDbg at Microsoft. Also on mastodon/fediverse as @tim@dbg.social
Systems Engineer
https://www.patrickmatula.com
CTO of Microsoft Azure, author of novels Rogue Code, Zero Day and Trojan Horse, Windows Internals, Sysinternals tools. Opinions are my own.
#Security #Azure #EntraID #XDR #MDE #Identity #M365 #AD #PKI #KQL
Microsoft MVP
Tweets and opinions are my own
Microsoft MVP (PowerShell) | AD Security Architect | Speaker | Author | Blogger | UG lead | Technology evangelist | PowerShell junkie | Husband | Father | Kayaker
#Veteran #InfoSec #Diversity #Inclusion #GadgetGeek #Whisky, neat. #Speaker - I talk about #security #animals and common decency. She/her. Author of The Security Squirrel Newsletter aka.ms/securitysquirrel
Principal Training Architect @ HackTheBox
CTF Addict
"Potentially a legit researcher"
he/him
Website: https://0xdf.gitlab.io/
YouTube: https://www.youtube.com/c/0xdf0xdf
Twitter: 0xdf_
Discord: 0xdf
Mastadon: 0xdf@infosec.exchange