1. X
  2. freefirex
Log inSign up
freefirex
162 posts
user avatar
freefirex
@freefirex2
Research Practice Lead @Trustedsec gamer and nature enthusiast
Joined January 2012
168
Following
1,744
Followers
RepliesRepliesMediaMedia
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

  • user avatar
    freefirex
    @freefirex2
    Jul 15
    Question to check my own bias's If you're operating on a system and you use make_token / steal_token or otherwise impersonate a user, which users HKCU would you expect to be referenced if you operated against the local registry?
    Primary / original user52.8%
    Impersonated user47.2%
    36 votesFinal results
    1.7K
  • user avatar
    freefirex
    @freefirex2
    May 6
    I don't know where this idea that you can't call CRT functions in bof's started coming from but it's just another function, you don't need to write your own memcpy, strcpy, memset, etc. Just link off to MSVCRT using DFR and your good to go
    CS-Situational-Awareness-BOF/src/common/bofdefs.h at ee9459cc4f42c6b025797bad22ffe8d9f1cf6487 ·...
    From github.com
    5.2K
  • user avatar
    freefirex
    @freefirex2
    Mar 12
    Here is the blog post for the CVE I mentioned yesterday! This was a fun find, and there's a few neat tools released to boot :D
    user avatar
    TrustedSec
    @TrustedSec
    Mar 12
    Who knew a #Windows shortcut could carry so much? In our new blog, @freefirex2 breaks down the newly patched CVE-2026-25185 and how a specific #ExtraData block combination silently coerces authentication without a single click. Read it now! hubs.la/Q046xPgJ0
    6K
  • user avatar
    freefirex
    @freefirex2
    Mar 11
    I caught my first CVE :D msrc.microsoft.com/update-guide/e… Blog post inbound at TrustedSec.com tomorrow!
    5.8K
  • user avatar
    freefirex
    @freefirex2
    Jan 9
    If after 1 month a company's bug bounty is still just trying to reproduce an issue when they were given: 1. A video 2. A tool to trigger said vulnerability 3. The function names and code path allowing the vulnerability. Maybe that bug bounty program isn't working as intended.
    5.4K