@nas_bench

Detection @Splunk & @cisco | previously @nextronsystems | @sigma_hq & @magicswordio maintainer | Eternal Learner

HAL
Joined August 2011
"How often have we changed the dream of progress, only to see that dream perverted? More often than not, haven't the machines we built to improve life shattered the lives of millions"
3
799
Nasreddine Bencherchali retweeted
Can app control stop a malicious skill from loading? ▶️ Watch the full episode: nitter.cf/magicswordio/status/20…
1
4
7
844
Hey codex build me an AI switch so I can stop claude if it goes rogue. Hey claude build me an AI switch so I can stop codex if it goes rogue. Hey @grok please verify
.@SenJohnKennedy wants AI models to have a “kill switch.” The Louisiana Republican says he plans to introduce a bill Wednesday requiring companies to be able to shut their models down if they move beyond human control. (1/3)
3
7
1,146
I'll be on PTO for 3 weeks. I request everyone to slow down in their research and attacks. We have to meaningfully cross this new AI era and align our vision for meaningful and safe future.
4
21
1,768
This is exactly how we talked about malware when we were kids after watching the Matrix for the first time.
Jacob Coxon's next interview on CBS News (ex Anthropic+Open AI researcher who resigned) "We can't just unplug it because it could be copying itself over to other computers. Like it's not that difficult to find yourself because an AI is just code. It could transfer itself over the internet to a different place and then you unplug it here, but it's actually still over there and maybe it makes 10,000 copies of itself and they're all cooperating." ---- From "CBS News" YouTube channel, (full video link in comment)
3
1
29
2,596
What I'm learning on Twitter is that most people in cyber never did any actual cyber. 🤡
56
32
3
406
26,199
Save your tokens by asking your questions on social media and to colleagues. People who want to be right will take it form there.
2
10
1,507
So to be a Microsoft MVP someone has to nominate you. Who do I need to talk to 🤔
5
9
2,377
Next thing you know, cyber is on the rise 🙈
You do realize that 1990s style signature IDS rules run at "machine speed", no? #random
1
1
6
1,634
Nasreddine Bencherchali retweeted
New blog: I’m in your logs now: deceiving analysts and blinding EDRs Based on my BlackHat talk from last year, so you don't have to listen to my voice ;) Some exploration into ETW spoofing and buffer pool exhaustion. medium.com/falconforce/im-in… #FalconForce #ETW #EDR #Evasion
3
74
4
259
16,391
Machine-speed attacks.... Agentic SOCs.... Autonomous everything.... Meanwhile, somewhere, an EDR is asking nicely for its process not to be killed. Also checks logs...4688 still not enabled 🙂‍↔️
5
5
37
2,923
Nasreddine Bencherchali retweeted
Microsoft’s signed Windows Defender Boot-Time Removal driver (BTR.sys) is a one-shot kernel component that decrypts an RC4-encrypted transaction list from an Alternate Data Stream and performs Ring-0 operations. An attacker with SeLoadDriverPrivilege can craft a valid encrypted config and load it early via a transient “Boot Bus Extender” service, abusing it as a trusted kernel primitive to bypass Tamper Protection, delete EDR/AV components before they start, drop malicious drivers, and gain persistence, without any vulnerability or BYOVD. No in-the-wild abuse has been observed. research.checkpoint.com/2026…
6
166
11
680
145,638
Nasreddine Bencherchali retweeted
Microsoft has failed to properly patch RoguePlanet (CVE-2026-50656), ShieldBreak, a PoC that demonstrates a full bypass to the previous patch is now public. github.com/MSNightmare/Shiel… The PoC works with the latest August 2026 patch
36
341
31
1,764
205,532
Nasreddine Bencherchali retweeted
How long would it take you to know if a Volt Typhoon technique ran on your endpoints today? Magic-Atomics runs real adversary techniques against your actual endpoints and tells you exactly what gets blocked and what doesn't. 4,800+ tests, 172 threat groups, one clear answer per test. clone it. 60 seconds to your first verdict 👇 github.com/magicsword-io/Mag… More here: magicsword.io/blog/magic-ato…
7
18
938
Nasreddine Bencherchali retweeted
Replying to @nas_bench
@nas_bench joined us live to break down what an EDR killer actually is and how it works at the kernel level. Tomorrow we're back for Part 2, this time with a live demo. How easy is it to actually build one? We're showing it live. 📅July 17 · 2:00 PM EST 🔗 Register: magicsword.io/prevention-lab… ▶️ Watch EDR Killers - Part 1: youtu.be/NPozyKrMj2c
2
4
560
Nasreddine Bencherchali retweeted
In case you missed it, Episode 6 | EDR Killers is now up. Thank you @nas_bench for joining us, great memes were shared 😂 🔗 youtu.be/NPozyKrMj2c #CyberSecurity #EDR #PreventionEngineering #MagicSword
2
5
31
1,894
Nasreddine Bencherchali retweeted
Episode 6 | EDR Killers nitter.cf/i/broadcasts/1AJEmmdbE…
3
6
669
Nasreddine Bencherchali retweeted
Episode 6 | EDR Killers nitter.cf/i/broadcasts/1OxwbboRl…
7
17
964
Nasreddine Bencherchali retweeted
The drivers behind The Gentlemen's EDR killer suite are already in LOLDrivers and prevented by MagicSword. IMFForceDelete (GentleKiller) 👉 loldrivers.io/drivers/6ca608… BdApiUtil (HexKiller) 👉 loldrivers.io/drivers/708650… ESET's months-long investigation into GentleKiller: 8 variants, each impersonating a legitimate product and abusing a different signed vulnerable driver. Plus HexKiller, ThrottleBlood, and HavocKiller, all standardized with the same evasion layer. Together targeting 400+ security processes across 48 vendors. New BYOVD proof-of-concepts turned into working exploits within days of public GitHub disclosure. 👀Full ESET breakdown welivesecurity.com/en/eset-r… 🎙️Today we're going deeper on EDR killers live with @nas_bench , detection engineer, threat hunter, and one of the sharpest people writing about Windows internals today. Register here: magicsword.io/prevention-lab… #BYOVD #LOLDrivers #CyberSecurity #Ransomware #ApplicationControl #PreventionEngineering
24
1
52
4,528