<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><link>https://bsky.app/profile/wetw0rk7.bsky.social</link><title>@wetw0rk7.bsky.social - wetw0rk</title><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3m3s2u3fvvs2f</link><description>Released my write for gaining a fundamental understanding of the Windows _SECURITY_DESCRIPTOR structure. I then created a custom Windows Kernel shellcode stub to perform process injection for privilege escalation which is also implemented in Sickle :P&#xA;&#xA;https://wetw0rk.github.io/posts/understanding-the-windows-_security_descriptor/</description><pubDate>22 Oct 2025 14:33 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3m3s2u3fvvs2f</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3m33f6ntmvs2k</link><description>Trick or Treat!! Would you still love my malware if it was a worm 🥺❤️?&#xA;&#xA;Sickle V4 has added a handler module for easy payload distribution and yes, you can do it over HTTPS!&#xA;&#xA;Download it here: https://github.com/wetw0rk/Sickle/</description><pubDate>13 Oct 2025 14:07 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3m33f6ntmvs2k</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lhpdm6xfg22z</link><description>Anyone hungry for a🍪? Today we learn about Stack Cookies! Also known as Canaries!&#xA;&#xA;This will be the last tutorial within the Windows Kernel Exploitation series.&#xA;&#xA;As of today all 10 tutorials are available for English speakers!&#xA;&#xA;https://wetw0rk.github.io/posts/0x09-return-of-the-stack-overflow/</description><pubDate>09 Feb 2025 00:08 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lhpdm6xfg22z</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lglcjdrw4c2c</link><description>Are you ready for an introduction to Windows Kernel Race Conditions?&#xA;&#xA;You can find the tutorial below :)&#xA;&#xA;https://wetw0rk.github.io/posts/0x07-introduction-to-windows-kernel-race-conditions/</description><pubDate>25 Jan 2025 16:13 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lglcjdrw4c2c</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lg5je2lkps22</link><description>Type Confusions pueden ser... difícil, especialmente cuando se trata de una versión más moderna de Windows. Hoy explotamos uno contra Windows 11 (x64). Un saludo a &#xA;@w4fz5uck5 y @xct_de! Por ayudarme a superar esto! &#xA;&#xA;Puedes encontrar el tutorial aquí:&#xA;&#xA;https://wetw0rk.github.io/posts/0x06-acerc%C3%A1ndose-a-windows-kernel-type-confusions-modernos/</description><pubDate>20 Jan 2025 04:38 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lg5je2lkps22</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lfzvpcr5nk2w</link><description>Type Confusions can be… confusing, especially when targeting a more modern version of Windows. Today we exploit one against Windows 11 (x64). Shoutout to @w4fz5uck5 and @xct_de for helping me get through this one!&#xA;&#xA;You can find the tutorial here:&#xA;&#xA;https://wetw0rk.github.io/posts/0x06-approaching-modern-windows-kernel-type-confusions/</description><pubDate>18 Jan 2025 18:08 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lfzvpcr5nk2w</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lffjkloyjs24</link><description>Mmm… Hrmmmmm… Mmm… mmm… Mm! Oh-hoh! Perdóname. Estaba absorto en mis pensamientos. Esta semana veremos una introducción a Type Confusions dentro del kernel de Windows! Más específicamente Windows 7 (x86).&#xA;&#xA;Puedes encontrar el tutorial aquí!&#xA;&#xA;https://wetw0rk.github.io/posts/0x05-introducci%C3%B3n-a-windows-kernel-type-confusion-vulnerabilidades/</description><pubDate>10 Jan 2025 15:37 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lffjkloyjs24</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lfcydnhltc2f</link><description>Mmm… Hrmmmmm… Mmm… mmm… Mm! Oh-hoh! Forgive me. I was absorbed in thought. This week, we’ll get an Introduction to Type Confusions within the Windows Kernel! More specifically Windows 7 (x86).&#xA;&#xA;You can find the link to the tutorial down below!&#xA;&#xA;https://wetw0rk.github.io/posts/0x05-introduction-to-windows-kernel-type-confusion-vulnerabilities/</description><pubDate>09 Jan 2025 15:24 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lfcydnhltc2f</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lf2eyfxqfc2i</link><description>Se me ocurrió algo más gracioso que 24… 25. Qué mejor manera de comenzar 2025 que con una introducción a una vulnerabilidad Write-What-Where dentro del kernel de Windows 7 (x86) y Windows 11 (x64)!&#xA;&#xA;Puedes encontrar el tutorial aquí:&#xA;&#xA;https://wetw0rk.github.io/posts/0x04-escribiendo-que-donde-en-el-kernel/</description><pubDate>06 Jan 2025 05:16 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lf2eyfxqfc2i</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lex7t5d3as2r</link><description>I thought of something funnier than 24… 25. What better way to start 2025 than with an introduction to a Write-What-Where vulnerability within the Windows 7 (x86) and Windows 11 (x64) Kernel!&#xA;&#xA;You can find the tutorial here:&#xA;&#xA;https://wetw0rk.github.io/posts/0x04-writing-what-where-in-the-kernel/</description><pubDate>04 Jan 2025 23:06 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lex7t5d3as2r</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3ldtwyetrjs2j</link><description>La semana pasada aprovechamos una vulnerabilidad de heap en el Windows 7 (x86) Kernel. Esta semana, un sistema más moderno - Windows 11 (x64)!&#xA;&#xA;El tutorial se puede encontrar aquí:&#xA;&#xA;https://wetw0rk.github.io/posts/0x03-acerc%C3%A1ndose-al-heap-moderno-del-windows-kernel/</description><pubDate>21 Dec 2024 22:25 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3ldtwyetrjs2j</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3ldtwxoosz22j</link><description>Last week, we successfully exploited a Windows Kernel vulnerability in the heap on a Windows 7 (x86) system. This week, we&#39;re targeting a more modern OS - Windows 11 (x64)!&#xA;&#xA;Check out the tutorial here:&#xA;&#xA;https://wetw0rk.github.io/posts/0x03-approaching-the-modern-windows-kernel-heap/</description><pubDate>21 Dec 2024 22:24 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3ldtwxoosz22j</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3ldi6qhrazc2m</link><description>Sickle v3.1.0 is out!! Shellcode generation is now supported and I&#39;ve added 9 new payloads including a reflective loader for Linux on both AARCH64 and x64! Along with a new module asm_shell which supports x86, x64, and AARCH64!&#xA;&#xA;Check it out here:&#xA;&#xA;github.com/wetw0rk/Sickle&#xA;https://github.com/wetw0rk/Sickle</description><pubDate>17 Dec 2024 06:12 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3ldi6qhrazc2m</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3ldfezroink2y</link><description>En la serie de Windows Kernel Exploitation hemos aprovechado la vulnerabilidad de “Stack Overflow” contra Windows 7 (x86) y Windows 11 (x64). Esta semana volveremos a Windows 7 (x86) y vamos a exploit un Use-After-Free dentro del Windows Kernel!&#xA;&#xA;https://wetw0rk.github.io/posts/0x02-introducci%C3%B3n-a-windows-kernel-uafs/</description><pubDate>16 Dec 2024 03:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3ldfezroink2y</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3ldclsds7a22j</link><description>So far in the Windows Kernel Exploitation series we have successfully exploited a Stack Overflow against both Windows 7 (x86) and Windows 11 (x64). This week you&#39;ll be getting an introduction on how to exploit a Use-After-Free within the Windows Kernel!&#xA;&#xA;https://wetw0rk.github.io/posts/0x02-introduction-to-windows-kernel-uafs/</description><pubDate>15 Dec 2024 00:49 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3ldclsds7a22j</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3ldagbl24d22c</link><description>It’s that time of the year, when you put your elf on a shelf and your ELFs in memory. Sickle now supports payload generation for reflective ELF loading!&#xA;&#xA;Currently AARCH64 (ARM64) and x86-64 supported.&#xA;&#xA;May your ELF payloads never touch disk!&#xA;&#xA;github.com/wetw0rk/Sickle</description><pubDate>14 Dec 2024 04:05 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3ldagbl24d22c</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lctakd3kns2g</link><description>Es hora de aprender a evitar las mitigaciones modernas de Windows! Como parte de este próximo tutorial, estoy revelando Violet Phosphorous, una técnica para evadir SMEP/VBS!&#xA;&#xA;Puedes encontrar el primer tutorial aqí:&#xA;&#xA;https://wetw0rk.github.io/posts/0x01-mat%C3%A1ndo-windows-kernel-mitigaciones/</description><pubDate>08 Dec 2024 22:18 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lctakd3kns2g</guid></item><item><link>https://bsky.app/profile/wetw0rk7.bsky.social/post/3lcp5gjlhns2q</link><description>It&#39;s time to learn how to bypass the latest mitigations deployed on Windows. As part of this next tutorial, I am dropping Violet Phosphorous, a SMEP/VBS bypass tested against the latest Windows 11 (x64) build as of today!&#xA;&#xA;You can find the post here:&#xA;&#xA;https://wetw0rk.github.io/posts/0x01-killing-windows-kernel-mitigations/</description><pubDate>07 Dec 2024 07:12 +0000</pubDate><guid isPermaLink="false">at://did:plc:ol6ncxi427sjerbcbyph7ozb/app.bsky.feed.post/3lcp5gjlhns2q</guid></item></channel></rss>