<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>probably not a mimic</description><link>https://bsky.app/profile/sixtyvividtails.bsky.social</link><title>@sixtyvividtails.bsky.social - sixtyvividtails</title><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3m2fsvhbzdk2w</link><description>Close your eyes and ✨imagine:&#xA;&#xA;From a low-integrity process (from LPAC even), you can inject your data anywhere you want:&#xA;privileged tasks, PPL/protected processes, the OS kernel itself, and VTL1 trustlets.&#xA;&#xA;Now open your eyes. It is not hypothetical.&#xA;It is the reality. Read it on page 33.&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>05 Oct 2025 00:14 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3m2fsvhbzdk2w</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lxnhrbcgnk2n</link><description>Error you may randomly get anytime you delete stuff: błąd 0x80070050.&#xA;Nevermind the shellful bin and Shellberus the dog (recycler shell32 dev).&#xA;&#xA;Error is due to rnd name generation for the bin: $R[A-Z0-9]{6}&lt;.ext&gt;.&#xA;Deleting 2 files: 36⁻⁶ ≈ 2⁻³¹ fail chance.&#xA;🎈Birthday paradox: 50% 🎲 for 54933 files.</description><pubDate>30 Aug 2025 21:00 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lxnhrbcgnk2n</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lx42ffrpr227</link><description>What is Volume Serial Number (aka VolId/VolumeId)?&#xA;For ntfs it&#39;s 64 bits at offset +0x48 from the volume start (in the $Boot file).&#xA;You see its lower dword with &#34;dir C:&#34;.&#xA;&#xA;But how it&#39;s calculated? Is it good for #DFIR?&#xA;👉 It&#39;s just a weak hash over 429.5 seconds of system time.</description><pubDate>23 Aug 2025 22:46 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lx42ffrpr227</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lwgbxdedqc2b</link><description>Greetings, fellow timetravelers. Today is Monday.&#xA;But if I could convince Pope Gregory XIII not to skip weekdays @1582-10-15, today could still be Friday!&#xA;&#xA;But there&#39;s a problem. To meet Pope, I gotta set clock on my Windows to the year 1582, yet it refuses: only allows 1601.&#xA;How to set it to 1582?</description><pubDate>15 Aug 2025 07:02 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lwgbxdedqc2b</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lvdzcypty22f</link><description>Finally, a script to estimate IQ of your PC!&#xA;Copypaste it into powershell console, get instant result!&#xA;&#xA;$9={[Runtime.InteropServices.Marshal]::&#xA;ReadInt64(1TB-64MB-+-$args[0]-shr9)};`&#xA;(&amp;$9 4KB)/(&amp;$9 (900.9MB/9.9/7-shr5))/`&#xA;25/(&amp;$9)*(2L-shl55)&#xA;&#xA;Is your PC smart?&#xA;Can you deduce what is that metric?</description><pubDate>01 Aug 2025 15:57 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lvdzcypty22f</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lscozn6z322k</link><description>Windows can seamlessly patch your code when it catches #GP. So called &#34;alignment fixup&#34;.&#xA;&#xA;KiOpPatchCode modifies user code: movaps-&gt;movups, movdqa-&gt;movdqu.&#xA;&#xA;Needs x64 code, and opt-in: SetErrorMode(SEM_NOALIGNMENTFAULTEXCEPT), or ProcessEnableAlignmentFaultFixup, or ThreadEnableAlignmentFaultFixup.</description><pubDate>23 Jun 2025 23:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lscozn6z322k</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lrnhgaxz2s2j</link><description>Did you know Windows has built-in RAM disk?&#xA;And not just your regular RAM disk. It&#39;s pmem/nvdimm, via built-in scmbus.sys facility!&#xA;&#xA;That means you can make 🦆🦆🦆  #dax volume, so data/image mappings (section views) will use &#34;drive&#34; directly!&#xA;No data persistence, no w10; only ws2022/w11+. EZ 📀 create:</description><pubDate>15 Jun 2025 12:23 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lrnhgaxz2s2j</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lqutqpvo7k2x</link><description>ntoskrnl #kASLR 🚫:&#xA;&#xA;r$t0=0;# and*77FFFF winload!MmArchInitialize L200;r$t0=@$exp;.while(by(@$t0)){r$t0=@$t0+1};ed@$t0-3 0;&#xA;ed MmArchKsegAddressRange 0 FFFFF800;&#xA;r$t0=SymCryptRngAesGenerate;ed@$t0 33CA8B48 E9D2;ed@$t0+6 memset-@$t0-A;&#xA;&#xA;ed OslGatherEntropy C3C033;&#xA;ed BlArchGetPerformanceCounter C3C033&#xA;&#xA;[contains quote post or other embedded content]</description><pubDate>05 Jun 2025 17:27 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lqutqpvo7k2x</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lqkukkpl7s2d</link><description>There are lots of misoptimisations in the OS kernel with /dynamicValueFixupSym.&#xA;&#xA;E.g. index check for SK PFN db — is it &#34;cmp rcx, 0x07FF&#39;FFFF&#39;FFFF&gt;&gt;3&#34;? Size is constant after all.&#xA;&#xA;Nope. Gotta load SKMM_PFN_DATABASE_END, SKMM_PFN_DATABASE, sub, shift, etc — dozens of extra instr, in a lot of places.</description><pubDate>01 Jun 2025 18:15 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lqkukkpl7s2d</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lojveekvx22z</link><description>Heard of #ContextJail?&#xA;It&#39;s a nasty new technique: puts target thread into ⓪ deadloop, for as long as you can afford. Requires THREAD_GET_CONTEXT right.&#xA;&#xA;The gist? Just spam NtGetContextThread(tgt).😸&#xA;Target will be jailed, running nt!PspGetSetContextSpecialApc 🔁.&#xA;&#xA;Src &amp; binary in [ALT].&#xA;&#xA;Usecases: ⤵️</description><pubDate>06 May 2025 22:06 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lojveekvx22z</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lmvevqsg322d</link><description>Kernel VA region for system images has size 512_GB (256_TB LA57).&#xA;And nt!MiAssignTopLevelRanges shuffles regions order before VA assignment.&#xA;&#xA;So why is ntoskrnl always in the first 31_GB from 0xFFFF_FF80_0000_0000?!&#xA;&#xA;That&#39;s just how winload.efi randomizes MmArchKsegBias.&#xA;&#xA;#KASLR #0xFFFFFF8000000000</description><pubDate>16 Apr 2025 00:53 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lmvevqsg322d</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3llnibquub22d</link><description>WinDbg script to check kCFG target function validity, and also to dump actual cfguard bitmap (which can be quite different from what&#39;s specified in the image GFIDS, needs more research): pastebin.com/64kujJNb.&#xA;&#xA;!check_cfguard &#34;nt!longjmp&#34;&#xA;&#xA;!dump_cfguard_bitmap &#34;nt&#34;, &#34;C:/cfguard_bitmap_ntoskrnl.bin&#34;&#xA;https://pastebin.com/64kujJNb</description><pubDate>31 Mar 2025 04:07 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3llnibquub22d</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lhwwto6pvc2g</link><description>Is your EDR a dump?&#xA;With crashdmp it literally is:&#xA;&#xA;cmd /v/c &#34;set R=reg add HKLM\SYSTEM\CurrentControlSet\Control\CrashControl /f /v&amp;!R! CrashDumpEnabled /d ୭ /t ൪&amp;!R! DumpFileSize /d ൬৬६ /t ៤&amp;for /f &#34;delims=*&#34; %i in (&#39;sc qc WinDefend^|find &#34;PATH_&#34;&#39;)do (set t=%i&amp;!R! DedicatedDumpFile /d !t:~๒੯,-១!)&#34;</description><pubDate>12 Feb 2025 00:41 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lhwwto6pvc2g</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lhsedvod3s2c</link><description>Stack /GS cookie - GuardStack &#34;__security_cookie&#34; - has protected NT for nearly 25 years.&#xA;&#xA;Do you know why higher word zeroed in 64-bit 🍪? Yep, it&#39;s against attacks like strcat/wcscat. But did you realize that&#39;s 𝗵𝗮𝗹𝗳-𝗯𝗿𝗼𝗸𝗲𝗻?!&#xA;Yes, xoring &#34;0000&#34; with ⓪ RSP gives &#34;FFFF&#34; 😹.&#xA;…and it&#39;s worse with LA57.</description><pubDate>10 Feb 2025 04:59 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lhsedvod3s2c</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lhaytgdr3c2q</link><description>24H2 has reduced KiCyclesPerClockQuantum by a factor of 6 - from ~(15.625/3) ms to ~(15.625/18) ms.&#xA;But QuantumReset compute changed too, so final revise is not so drastic. Was: 31.25 to 93.75 ms; now: 15.625 to 31.25 ms, yet min is 1.74 ms.&#xA;&#xA;But WTF: clock interrupts every 2 ms across *each* CPU!</description><pubDate>03 Feb 2025 07:18 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lhaytgdr3c2q</guid></item><item><link>https://bsky.app/profile/sixtyvividtails.bsky.social/post/3lamvrf3fgk2w</link><description>Nel mezzo del cammin di nostra vita,&#xA;mi ritrovai per una selva oscura,&#xA;ché la diritta via era smarrita.</description><pubDate>10 Nov 2024 22:59 +0000</pubDate><guid isPermaLink="false">at://did:plc:jxtkgvs5pvvanhchjvldmtvi/app.bsky.feed.post/3lamvrf3fgk2w</guid></item></channel></rss>