Yarden Shafir's Avatar

Yarden Shafir

@yardenshafir.bsky.social

A circus artist with a visual studio license

1,171 Followers  |  35 Following  |  54 Posts  |  Joined: 04.05.2023  |  1.9074

Latest posts by yardenshafir.bsky.social on Bluesky

Havenโ€™t uploaded them but happy to do that if you find them useful on their own :)

29.05.2025 16:38 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
BlueHat IL 2025 - Yarden Shafir - Look, Maโ€”No Privileges! How Windows Gives You Kernel Pointers...
YouTube video by Microsoft Israel R&D Center BlueHat IL 2025 - Yarden Shafir - Look, Maโ€”No Privileges! How Windows Gives You Kernel Pointers...

Looks like BlueHatIL talks are online now, so hereโ€™s my talk for anyone who wanted to learn about the latest episode of KASLR and couldnโ€™t make it: www.youtube.com/watch?v=Dk2r...

29.05.2025 01:30 โ€” ๐Ÿ‘ 8    ๐Ÿ” 3    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

I wonder if Google maps can give me driving directions to TraceView, Tennessee

25.04.2025 18:53 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

AI search engines are the future

25.04.2025 17:54 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Microsoft threat actor found in the wild

07.04.2025 05:17 โ€” ๐Ÿ‘ 7    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

To me this looks like an oversight by Microsoft, not an intentional thing, but Iโ€™m not sure windows defender ever blocked any drivers through the ELAM callback so I donโ€™t know if this changes much.

Other EDRs: do you use the ELAM blocking functionality or only use it for the cert?

03.04.2025 10:13 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Wdboot.sys driver entry, function is empty and has no functionality.

Wdboot.sys driver entry, function is empty and has no functionality.

For about a year now, WdBoot.sys essentially does nothing. Microsoft installs 2 versions:
- \System32\drivers\wdboot.sys is the โ€œfullโ€, functional version
- \System32\drivers\wd\wdboot.sys is the โ€œemptyโ€ version, which is the one being updated and loaded.

Does anyone know the reason behind this?

03.04.2025 10:12 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

The dying words of the American empire will be โ€œI donโ€™t think this code does anything. Iโ€™ll go ahead and delete that.โ€

29.03.2025 04:47 โ€” ๐Ÿ‘ 17    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Oh look theyโ€™re going to vibe program the SSA systems. Iโ€™m sure this will be perfectly fine and will cause no issues.

29.03.2025 04:46 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Knowing they eat steak makes them even scarier

22.03.2025 01:21 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Kookaburra

Kookaburra

This cute little thing sounds like a witch laughing in a dark forest and has tried to kill me twice so far

20.03.2025 14:03 โ€” ๐Ÿ‘ 10    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

I was told Australia is scary but didnโ€™t expect to land and immediately get threatened by a public bus

16.03.2025 02:04 โ€” ๐Ÿ‘ 7    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Windows is going through some stuff right now

06.03.2025 21:33 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Blog: Zen and the Art of Microcode Hacking This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.

"Zen and the Art of Microcode Hacking"

Tragic signature bypass enables custom microcode loading on AMD processors, and a tool to do it. The blog is extremely well written and provides concise explanations of topics mentioned + plenty of resources! A must read.

bughunters.google.com/blog/5424842...

06.03.2025 02:32 โ€” ๐Ÿ‘ 36    ๐Ÿ” 12    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Small anecdote about thread priorities and throttling on Windows 11:
Iโ€™m downloading a large file.
Estimated time left: 28 minutes.
Open notepad, put it as the front window. Download time left: 57 minutes.
Close notepad, browser back in front. Time left: 27 minutes.

06.03.2025 20:21 โ€” ๐Ÿ‘ 3    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

Iโ€™m not saying you definitely have to go to @BlueHatIL this year, Iโ€™m just letting you know itโ€™s free, by the beach and Iโ€™ll be there dropping kernel pointers to anyone who asks nicely

05.03.2025 23:07 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Meet Rayhunter: A New Open Source Tool from EFF to Detect Cellular Spying Rayhunter is a new open source tool weโ€™ve created that runs off an affordable mobile hotspot that we hope empowers everyone, regardless of technical skill, to help search out cell-site simulators (CSS...

I work with cool people who do cool things: www.eff.org/deeplinks/20...

05.03.2025 22:32 โ€” ๐Ÿ‘ 327    ๐Ÿ” 104    ๐Ÿ’ฌ 14    ๐Ÿ“Œ 9
Post image

Celebrating flat fuck Friday

28.02.2025 21:21 โ€” ๐Ÿ‘ 10    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Wanted to live tweet so bad but also didnโ€™t wanna look away from the show it was so good. And the best singer in this was Janet!

20.02.2025 18:03 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Not that I saw but there were some of the usual shout outs and the narrator responded to all of them

19.02.2025 21:25 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

โ€œIt was a strange nightโ€ฆ how strange? As strange as the strangest thing going through Trumpโ€™s headโ€

19.02.2025 20:19 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This is a full theatre production, live singing and all. This is everything I could ever ask for.

The narrator is brilliant and Iโ€™m crying laughing.

19.02.2025 20:19 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Post image

Going to a Rocky Horror show in a quiet UK town and the crowd is almost entirely old British people so Iโ€™m expecting an incredible time

19.02.2025 19:33 โ€” ๐Ÿ‘ 7    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
BlueHat IL 2025- Congratulations- your submission to the main hall was accepted!

BlueHat IL 2025- Congratulations- your submission to the main hall was accepted!

๐ŸŽ‰๐ŸŽ‰

16.02.2025 08:56 โ€” ๐Ÿ‘ 10    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image

More baking!

09.02.2025 18:15 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Every single Canadian stereotype is correct. It is -4c (24f) today and I've seen one people walking around in shorts and another one in a short-sleeved t-shirt. Not a single person is wearing a hat.

07.02.2025 19:38 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

Did a bit of baking this weekend

02.02.2025 14:20 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Of course!

31.01.2025 15:30 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Good morning

29.01.2025 16:35 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Does anyone know companies hiring for entry level roles (in Canada/remote)? And I mean *real* entry level, not degree + 2 certs + 3 years experience โ€œentry levelโ€.

Not just cybersecurity, any entry level roles at all, in any area.

27.01.2025 16:40 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@yardenshafir is following 20 prominent accounts