Log inSign up
Check Point Research
592 posts
user avatar
Check Point Research
@_CPResearch_
Fighting cyber threats one research at a time. News from Check Point’s (@checkpointSW) Research team.
The Internet
research.checkpoint.com
Joined April 2018
120
Following
25K
Followers
  • user avatar
    Check Point Research
    @_CPResearch_
    Jul 14, 2020
    We discovered a 17-year-old vulnerability in all of Windows DNS Servers. SIGRed (CVE-2020-1350) is a wormable, critical vulnerability that can be used to achieve full Domain Administrator privileges.
    research.checkpoint.com
    SIGRed - Resolving Your Way into Domain Admin: Exploiting a 17 Year-old Bug in Windows DNS Servers...
    Research by: Sagi Tzadik Introduction DNS, which is often described as the “phonebook of the internet”, is a network protocol for translating human-friendly computer hostnames into IP addresses....
  • user avatar
    Check Point Research
    @_CPResearch_
    Mar 1, 2020
    We launched our new Malware Evasion Encyclopedia, which contains over 50 techniques used by various malwares to detect virtualized and sandboxed environments. We hope this effort would allow for better understanding and analysis of modern attacks.
    evasions.checkpoint.com
    Malware Evasion Encyclopedia
    Evasion techniques
  • user avatar
    Check Point Research
    @_CPResearch_
    Dec 18, 2020
    Confirmed! TEARDROP the memory-only dropper from the #SUNBURST attack was uploaded to VirusTotal and available for analysis. virustotal.com/gui/file/6e405…
  • user avatar
    Check Point Research
    @_CPResearch_
    Mar 10, 2022
    Based on @ContiLeaks, we made an interactive graph of Conti members' relations and share some insights: 🥳Impressive level of self-organization 🥳Bonuses, prizes and bring-your-friend programs 🥳New friends and career growth! 👀Looming threat of prison research.checkpoint.com/2022/leaks-of-…
  • user avatar
    Check Point Research
    @_CPResearch_
    Feb 23, 2021
    A fresh BlueKeep exploit + loader, written by the exploit developer known as "PlayBit" and named by him "BlackKeep". The sample is available on Virus Total (6/68): virustotal.com/gui/file/06129…
  • user avatar
    Check Point Research
    @_CPResearch_
    Aug 5, 2020
    Based on the insights from of our research, we are happy to present our new Anti-Debug Encyclopedia. All the techniques which are described in this encyclopedia are implemented in our ShowStopper open-source project as well!
    anti-debug.checkpoint.com
    Anti-Debug Tricks
    Anti-Debug Tricks
  • user avatar
    Check Point Research
    @_CPResearch_
    Jun 28, 2022
    #BREAKING We found files related to the attack against the Steel Industry in Iran. Initial analysis shows that the malware is connected to the attacks against Iran Railways last year, an attack that was thoroughly described in our previous research. Here's what we know so far >>
  • user avatar
    Check Point Research
    @_CPResearch_
    Jul 25, 2024
    In this blog we introduce Thread-Name Calling - A new process injection technique using Thread Name. We also discuss various scenarios in which this not widely-known API can be used for offense.
    Thread Name-Calling - using Thread Name for offense - Check Point Research
    From research.checkpoint.com
    169K
  • user avatar
    Check Point Research
    @_CPResearch_
    Dec 12, 2018
    This is the story of how we discovered over 50 critical vulnerabilities in Adobe Reader research.checkpoint.com/50-adobe-cves-… #adobe
    50 CVEs in 50 Days: Fuzzing Adobe Reader - Check Point Research
    From research.checkpoint.com
  • user avatar
    Check Point Research
    @_CPResearch_
    Sep 24, 2020
    A malicious picture can trigger an Instagram vulnerability potentially resulting in RCE on mobile devices. Read our full technical paper here:
    #Instagram_RCE: Code Execution Vulnerability in Instagram App for Android and iOS - Check Point...
    From research.checkpoint.com
  • user avatar
    Check Point Research
    @_CPResearch_
    Sep 21, 2022
    For a reverse engineer, the ability to directly call a function from the analyzed binary can be a shortcut that bypasses a lot of grief. In this article, we explore and compare 3 ways of invoking functions: IDA Appcall, Dumpulator, and Unicorn Engine.
    Native function and Assembly Code Invocation - Check Point Research
    From research.checkpoint.com
  • user avatar
    Check Point Research
    @_CPResearch_
    Feb 5, 2019
    Reverse RDP Attack - How we broke the 3 most popular RDP clients. research.checkpoint.com/reverse-rdp-at…
  • user avatar
    Check Point Research
    @_CPResearch_
    Jun 6, 2023
    A deep dive into reverse-engineering Rust core features
    Rust Binary Analysis, Feature by Feature - Check Point Research
    From research.checkpoint.com
    38K
  • user avatar
    Check Point Research
    @_CPResearch_
    Feb 14, 2024
    Today, we're disclosing an overlooked, wide-impact bug/attack vector affecting the Windows/COM ecosystem, dubbed #MonikerLink. In Outlook, the bug's impact is far and wide: from leaking NTLM creds to RCE. The same issue may exist in other software, too.
    The Risks of the #MonikerLink Bug in Microsoft Outlook and the Big Picture - Check Point Research
    From research.checkpoint.com
    69K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up