برای درک اینکه یک فرآیند چیه باید وضعیت دستگاه رو درک کنیم:
یک برنامه هنگام اجرا چه چیزی رو میتونه بخونه یا اپدیت کنه
در هر زمان چه بخشهایی از دستگاه برای اجرای این برنامه مهمن؟
یکی از اجزای بارز وضعیت دستگاه که یک فرآیند رو تشکیل میده حافظه اونه
دستورالعمل ها در حافظه قرار دارن داده هایی که برنامه در حال اجرا میخونه و مینویسه هم در حافظه قرار دارن پس حافظه ای که فرآیند میتونه به اون آدرس بده به اسم فضای آدرس اونه بخشی از فرآینده
همچنین بخشی از وضعیت دستگاه فرآیند رجیستر ها هستن بیشتر دستور العملها به درستی رجیستر ها رو میخونن یا اپدیت می
کنن پس به وضوح برای اجرای فرآیند مهمن توجه داشته باشید که برخی رجیسترهای خاص وجود دارند که بخشی از این حالت ماشین رو تشکیل میدن
مثال:
شمارنده برنامه (PC) (که بعضی وقتا اشاره گر دستورالعمل یا IP بهش میگن
To understand what a process is we need to understand the state of the machine:
What can a program read or update while it is running?
What parts of the machine are important to the execution of the program at any given time?
One of the most obvious components of the machine state that makes up a process is its memory
Instructions are in memory The data that the program reads and writes while it is running is also in memory So the memory that a process can address is called its address space
Also part of the state of the machine are the registers Most instructions read or update registers so it is important to understand that there are certain registers that make up this state of the machine
For example:
The program counter (PC) (sometimes called the instruction pointer or IP)
@reverseengine
یک برنامه هنگام اجرا چه چیزی رو میتونه بخونه یا اپدیت کنه
در هر زمان چه بخشهایی از دستگاه برای اجرای این برنامه مهمن؟
یکی از اجزای بارز وضعیت دستگاه که یک فرآیند رو تشکیل میده حافظه اونه
دستورالعمل ها در حافظه قرار دارن داده هایی که برنامه در حال اجرا میخونه و مینویسه هم در حافظه قرار دارن پس حافظه ای که فرآیند میتونه به اون آدرس بده به اسم فضای آدرس اونه بخشی از فرآینده
همچنین بخشی از وضعیت دستگاه فرآیند رجیستر ها هستن بیشتر دستور العملها به درستی رجیستر ها رو میخونن یا اپدیت می
کنن پس به وضوح برای اجرای فرآیند مهمن توجه داشته باشید که برخی رجیسترهای خاص وجود دارند که بخشی از این حالت ماشین رو تشکیل میدن
مثال:
شمارنده برنامه (PC) (که بعضی وقتا اشاره گر دستورالعمل یا IP بهش میگن
To understand what a process is we need to understand the state of the machine:
What can a program read or update while it is running?
What parts of the machine are important to the execution of the program at any given time?
One of the most obvious components of the machine state that makes up a process is its memory
Instructions are in memory The data that the program reads and writes while it is running is also in memory So the memory that a process can address is called its address space
Also part of the state of the machine are the registers Most instructions read or update registers so it is important to understand that there are certain registers that make up this state of the machine
For example:
The program counter (PC) (sometimes called the instruction pointer or IP)
@reverseengine
❤1
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained
Vulnerabilities
https://hybrid-analysis.blogspot.com/2025/10/a-deep-dive-into-warlock-ransomware.html
@reverseengine
Vulnerabilities
https://hybrid-analysis.blogspot.com/2025/10/a-deep-dive-into-warlock-ransomware.html
@reverseengine
Blogspot
A Deep Dive Into Warlock Ransomware Deployed Via ToolShell SharePoint Chained Vulnerabilities
Author(s): Vlad Pasca Warlock ransomware was deployed by exploiting the SharePoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 The ma...
👍1
Coruna is a multi-stage, multi-platform browser exploit framework targeting Apple's Safari/WebKit engine on ARM64 (arm64e) devices running iOS and macOS
https://www.nadsec.online/blog/coruna-technical-analysis
@reverseengine
https://www.nadsec.online/blog/coruna-technical-analysis
@reverseengine
www.nadsec.online
Coruna: Complete Technical Teardown
6,596-line static RE of a state-grade iOS/macOS watering-hole exploit chain. Full class taxonomy, algorithm reconstruction, IOCs, and YARA rules.
Mergen
Mergen is a deobfuscation tool that leverages LLVM IR and assembly parsing to reverse engineer obfuscated code.
@reverseengine
Mergen is a deobfuscation tool that leverages LLVM IR and assembly parsing to reverse engineer obfuscated code.
https://github.com/NaC-L/Mergen@reverseengine
GitHub
GitHub - NaC-L/Mergen: Deobfuscation via optimization with usage of LLVM IR and parsing assembly.
Deobfuscation via optimization with usage of LLVM IR and parsing assembly. - NaC-L/Mergen
Pwning Minecraft: 4-Byte Heap Overflow to RCE
https://osec.io/blog/2026-06-02-minecraft-heap-overflow-to-rce
@reverseengine
https://osec.io/blog/2026-06-02-minecraft-heap-overflow-to-rce
@reverseengine
OtterSec
Pwning Minecraft: 4-byte heap overflow to RCE
We achieved RCE in Minecraft Bedrock, turning a 4-byte heap overflow into complete client compromise. Learn how a universal, Bedrock-specific technique is used to bypass ASLR and achieve arbitrary read/write primitives.
Analyzing the PayloadRestrictions.dll Export Address Filtering
https://windows-internals.com/an-exercise-in-dynamic-analysis
@reverseengine
https://windows-internals.com/an-exercise-in-dynamic-analysis
@reverseengine
GitHub - bytecode77/r77-rootkit:
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections
https://github.com/bytecode77/r77-rootkit
@reverseengine
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections
https://github.com/bytecode77/r77-rootkit
@reverseengine
GitHub
GitHub - bytecode77/r77-rootkit: Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections…
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc. - bytecode77/r77-rootkit
EVENmonitor
A monitoring tool for the Windows Event log in pure python
https://github.com/NeffIsBack/EVENmonitor
@reverseengine
A monitoring tool for the Windows Event log in pure python
https://github.com/NeffIsBack/EVENmonitor
@reverseengine
GitHub
GitHub - NeffIsBack/EVENmonitor: Monitor the Windows Event Log with grep-like features or filtering for specific Event IDs
Monitor the Windows Event Log with grep-like features or filtering for specific Event IDs - NeffIsBack/EVENmonitor
kwcmd
Kwcmd is a minimal Linux backdoor designed for stealthy network access
https://github.com/proxy-bar/kwcmd
@reverseengine
Kwcmd is a minimal Linux backdoor designed for stealthy network access
https://github.com/proxy-bar/kwcmd
@reverseengine
GitHub
GitHub - proxy-bar/kwcmd: hidden linux backdoor
hidden linux backdoor. Contribute to proxy-bar/kwcmd development by creating an account on GitHub.
DllShimmer
DllShimmer is a tool for rapidly creating and injecting backdoors into DLLs, facilitating remote control and exploitation of target processes. It simplifies the process of DLL hijacking for security research and potentially malicious activity.
https://github.com/Print3M/DllShimmer
@reverseengine
DllShimmer is a tool for rapidly creating and injecting backdoors into DLLs, facilitating remote control and exploitation of target processes. It simplifies the process of DLL hijacking for security research and potentially malicious activity.
https://github.com/Print3M/DllShimmer
@reverseengine
GitHub
GitHub - Print3M/DllShimmer: Weaponize DLL hijacking easily. Backdoor any function in any DLL.
Weaponize DLL hijacking easily. Backdoor any function in any DLL. - Print3M/DllShimmer
کرنل چیه؟
تا اینجا گفتیم سیستم عامل بین برنامهها و سختافزار قرار میگیره
اما سوال مهم:
آیا کل سیستم عامل همیشه در حال اجراست؟
نه
در قلب هر سیستم عامل یک بخش بسیار مهم وجود داره به نام Kernel یا هسته
کرنل مهمترین قسمت سیستم عامله و مستقیما با سختافزار کار میکنه
یک مثال ساده:
فرض کنید یک شرکت بزرگ داریم:
کارمندان = برنامهها
ساختمان و تجهیزات = سختافزار
مدیرعامل = Kernel
کارمندها نمیتونن هر کاری خواستن انجام بدن
مثلا نمیتونن مستقیم وارد اتاق سرور بشن یا تجهیزات رو بردارن
باید درخواست شون رو به مدیر عامل یا سیستم مدیریتی بدن
کرنل هم دقیقا همین نقش رو داره
کرنل چه کارهایی انجام میده؟
مدیریت پردازنده (CPU)
تصمیم میگیرد:
کدوم برنامه اجرا بشه؟
چه مدت اجرا بشه؟
چه زمانی متوقف بشه؟
مدیریت حافظه (RAM)
تصمیم میگیرد:
هر برنامه چقدر حافظه بگیره؟
حافظه برنامهها از هم جدا بمونه
یک برنامه نتونه حافظه برنامه دیگه ای رو بخونه
مدیریت فایلها
وقتی برنامهای فایل باز میکنه:
Plain text
در نهایت کرنل مسئول انجام این عملیاته
مدیریت دستگاهها
مثل:
کیبورد
ماوس
هارد
کارت شبکه
USB
همه از طریق کرنل کنترل میشن
User Mode و Kernel Mode
یکی از مهمترین مفاهیم کل سیستم
عامل همینجاست
پردازنده معمولا دو حالت اجرا داره:
User Mode
جایی که برنامههای عادی اجرا میشن
مثل:
در این حالت برنامه محدودیت داره
Kernel Mode
جایی که کرنل اجرا میشه
در این حالت تقریبا دسترسی کامل به سیستم وجود دارد.
چرا این جداسازی مهمه؟
فرض کنید یک برنامه باگ داشته باشه
اگر مستقیم به سختافزار دسترسی کامل داشته باشه:
سیستم کرش میکنه
اطلاعات خراب میشن
امنیت از بین میره
برای همین سیستمعامل برنامهها رو در User Mode نگه میداره
ارتباط برنامه با کرنل چجوریه؟
از طریق System Call
مثلا وقتی برنامه میخاد:
فایل باز کنه
حافظه بگیره
پردازه جدید بسازه
در واقع از کرنل درخواست کمک میکنه
نکته مهم برای مهندسی معکوس:
وقتی داخل دیباگر توابعی مثل اینها رو میبینید:
C
پشت صحنه تقریبا همه اونا در نهایت به کرنل میرسن
به همین دلیل مهندس معکوس باید همیشه بدوند:
الان کد در User Mode اجرا میشه یا در Kernel Mode؟
این سوال پایه بسیاری از مباحث بعدی مثل:
هست
What is a kernel?
So far, we have said that the operating system is located between the programs and the hardware
But the important question:
Is the entire operating system always running?
No
At the heart of every operating system is a very important part called the Kernel
The kernel is the most important part of the operating system and works directly with the hardware
A simple example:
Let's assume we have a large company:
Employees = programs
Buildings and equipment = hardware
CEO = Kernel
Employees cannot do whatever they want
For example, they cannot directly enter the server room or remove equipment
They must direct their requests to the CEO or system management
The kernel has exactly the same role
What does the kernel do?
Processor (CPU) management
Decides:
Which program to run?
How long to run?
When to stop?
Memory Management (RAM)
Decides:
How much memory should each program take?
Program memory should be kept separate
A program cannot read another program's memory
File Management
When a program opens a file:
Plain text
Ultimately, the kernel is responsible for performing this operation
Device Management
For example:
Keyboard
Mouse
Hardware
Network Card
USB
All are controlled by the kernel
User Mode and Kernel Mode
One of the most important concepts of the entire operating system is here
The processor usually has two execution modes:
User Mode
Where normal programs are executed
For example:
In this mode, the program has restrictions
Kernel Mode
Where the kernel is executed
In this mode, there is almost complete access to the system.
Why is this separation important?
Suppose a program has a bug
If it has full access to the hardware directly:
The system crashes
Data gets corrupted
Security is lost
That's why the operating system keeps programs in User Mode
تا اینجا گفتیم سیستم عامل بین برنامهها و سختافزار قرار میگیره
اما سوال مهم:
آیا کل سیستم عامل همیشه در حال اجراست؟
نه
در قلب هر سیستم عامل یک بخش بسیار مهم وجود داره به نام Kernel یا هسته
کرنل مهمترین قسمت سیستم عامله و مستقیما با سختافزار کار میکنه
یک مثال ساده:
فرض کنید یک شرکت بزرگ داریم:
کارمندان = برنامهها
ساختمان و تجهیزات = سختافزار
مدیرعامل = Kernel
کارمندها نمیتونن هر کاری خواستن انجام بدن
مثلا نمیتونن مستقیم وارد اتاق سرور بشن یا تجهیزات رو بردارن
باید درخواست شون رو به مدیر عامل یا سیستم مدیریتی بدن
کرنل هم دقیقا همین نقش رو داره
کرنل چه کارهایی انجام میده؟
مدیریت پردازنده (CPU)
تصمیم میگیرد:
کدوم برنامه اجرا بشه؟
چه مدت اجرا بشه؟
چه زمانی متوقف بشه؟
مدیریت حافظه (RAM)
تصمیم میگیرد:
هر برنامه چقدر حافظه بگیره؟
حافظه برنامهها از هم جدا بمونه
یک برنامه نتونه حافظه برنامه دیگه ای رو بخونه
مدیریت فایلها
وقتی برنامهای فایل باز میکنه:
Plain text
read()
write()
open()
در نهایت کرنل مسئول انجام این عملیاته
مدیریت دستگاهها
مثل:
کیبورد
ماوس
هارد
کارت شبکه
USB
همه از طریق کرنل کنترل میشن
User Mode و Kernel Mode
یکی از مهمترین مفاهیم کل سیستم
عامل همینجاست
پردازنده معمولا دو حالت اجرا داره:
User Mode
جایی که برنامههای عادی اجرا میشن
مثل:
Chrome
Firefox
Telegram
Notepad
در این حالت برنامه محدودیت داره
Kernel Mode
جایی که کرنل اجرا میشه
در این حالت تقریبا دسترسی کامل به سیستم وجود دارد.
چرا این جداسازی مهمه؟
فرض کنید یک برنامه باگ داشته باشه
اگر مستقیم به سختافزار دسترسی کامل داشته باشه:
سیستم کرش میکنه
اطلاعات خراب میشن
امنیت از بین میره
برای همین سیستمعامل برنامهها رو در User Mode نگه میداره
ارتباط برنامه با کرنل چجوریه؟
از طریق System Call
مثلا وقتی برنامه میخاد:
فایل باز کنه
حافظه بگیره
پردازه جدید بسازه
در واقع از کرنل درخواست کمک میکنه
نکته مهم برای مهندسی معکوس:
وقتی داخل دیباگر توابعی مثل اینها رو میبینید:
C
CreateProcess
CreateThread
VirtualAlloc
ReadFile
WriteFile
پشت صحنه تقریبا همه اونا در نهایت به کرنل میرسن
به همین دلیل مهندس معکوس باید همیشه بدوند:
الان کد در User Mode اجرا میشه یا در Kernel Mode؟
این سوال پایه بسیاری از مباحث بعدی مثل:
Process
Memory
System Call
Driver
Windows Internals
هست
What is a kernel?
So far, we have said that the operating system is located between the programs and the hardware
But the important question:
Is the entire operating system always running?
No
At the heart of every operating system is a very important part called the Kernel
The kernel is the most important part of the operating system and works directly with the hardware
A simple example:
Let's assume we have a large company:
Employees = programs
Buildings and equipment = hardware
CEO = Kernel
Employees cannot do whatever they want
For example, they cannot directly enter the server room or remove equipment
They must direct their requests to the CEO or system management
The kernel has exactly the same role
What does the kernel do?
Processor (CPU) management
Decides:
Which program to run?
How long to run?
When to stop?
Memory Management (RAM)
Decides:
How much memory should each program take?
Program memory should be kept separate
A program cannot read another program's memory
File Management
When a program opens a file:
Plain text
read()
write()
open()
Ultimately, the kernel is responsible for performing this operation
Device Management
For example:
Keyboard
Mouse
Hardware
Network Card
USB
All are controlled by the kernel
User Mode and Kernel Mode
One of the most important concepts of the entire operating system is here
The processor usually has two execution modes:
User Mode
Where normal programs are executed
For example:
Chrome
Firefox
Telegram
Notepad
In this mode, the program has restrictions
Kernel Mode
Where the kernel is executed
In this mode, there is almost complete access to the system.
Why is this separation important?
Suppose a program has a bug
If it has full access to the hardware directly:
The system crashes
Data gets corrupted
Security is lost
That's why the operating system keeps programs in User Mode
❤2
How does the program communicate with the kernel?
Through System Call
For example, when the program wants to:
Open a file
Get memory
Create a new process
It actually asks the kernel for help
Important point for reverse engineering:
When you see functions like these in the debugger:
C
Behind the scenes, almost all of them end up in the kernel
That's why the reverse engineer should always know:
Is the code currently running in User Mode or Kernel Mode?
This question is the basis for many subsequent topics such as:
@reverseengine
Through System Call
For example, when the program wants to:
Open a file
Get memory
Create a new process
It actually asks the kernel for help
Important point for reverse engineering:
When you see functions like these in the debugger:
C
CreateProcess
CreateThread
VirtualAlloc
ReadFile
WriteFile
Behind the scenes, almost all of them end up in the kernel
That's why the reverse engineer should always know:
Is the code currently running in User Mode or Kernel Mode?
This question is the basis for many subsequent topics such as:
Process
Memory
System Call
Driver
Windows Internals
@reverseengine
❤1
Diving into the MS-RPC protocol and how to automate vulnerability research using a fuzzing approach.
https://www.incendium.rocks/posts/Automating-MS-RPC-Vulnerability-Research
@reverseengine
https://www.incendium.rocks/posts/Automating-MS-RPC-Vulnerability-Research
@reverseengine
Remco van der Meer
Automating MS-RPC vulnerability research
Diving into the MS-RPC protocol and how to automate vulnerability research using a fuzzing approach.
Escalating privilege in the system from unsigned driver using throttlestop vulnerability
https://github.com/D4rkks/CVE-2025-7771-Vulnerability-Exploration
@reverseengine
https://github.com/D4rkks/CVE-2025-7771-Vulnerability-Exploration
@reverseengine
GitHub
GitHub - D4rkks/CVE-2025-7771-Vulnerability-Exploration: Escalating privilege in the system from unsigned driver using throttlestop…
Escalating privilege in the system from unsigned driver using throttlestop vulnerability - D4rkks/CVE-2025-7771-Vulnerability-Exploration
Forwarded from Source Byte
Static Devirtualization of Themida
This article demonstrates devirtualization of CodeVirtualizer/Themida protected code, however the techniques described here apply to pretty much every virtual machine based obfuscator. Only requiring some minor modifications to support each of them. The following is a non-exhaustive list of obfuscators that can be reduced using the technique described in this article.
https://back.engineering/blog/09/05/2026/
This article demonstrates devirtualization of CodeVirtualizer/Themida protected code, however the techniques described here apply to pretty much every virtual machine based obfuscator. Only requiring some minor modifications to support each of them. The following is a non-exhaustive list of obfuscators that can be reduced using the technique described in this article.
https://back.engineering/blog/09/05/2026/