Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

安坂星海 Azaka || VTuber

@still@infosec.exchange
  • Open on infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber
⊹˚. Employed Threat Intel Researcher
♡‧₊˚ SV Cover Artist
✧・゚https://azaka.fun
*:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

0 Followers
0 Following
18 Posts
Joined November 05, 2022
Links:
https://links.azaka.fun/
Twitch:
https://twitch.tv/azakasekai

Posts

Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · 3d ago
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
Replying to @usernomnomnom@mastodon.social
@usernomnomnom@mastodon.social @syntaxxor@sk.girlthi.ng I don't even think Secure Boot disablement is required these days anymore. I recently installed arch on a device and live Ubuntu on another and things just worked™️
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · 4d ago
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
Replying to @GossiTheDog@cyberplace.social
@GossiTheDog@cyberplace.social Valve apparently issued a notice to European Valve hardware customers already for this
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · 6d ago
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
you know Microsoft fucked up when your non-tech-savvy friend has moved to Linux all by themselves
0
1
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Aug 06, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
It's been a few days since I got my Pebble Time 2 It honestly feels like getting an old friend back everything just works and is all still so familiar - even the apps I used a decade ago
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Aug 05, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
I think I think I need to cut down my work and relax a little - I've been working on so many things nonstop it's actually killing my health I've had so much personal projects and matters to work on in between and after work that I'm missing meals, cutting sleep hours
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 30, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
the latest NIKKE event story is fucked up bro
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 28, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
Replying to @still@infosec.exchange

I've had so much friction in general when trying to PR for new rules this time around.

https://github.com/mandiant/capa-rules/pull/1171 https://github.com/mandiant/capa-rules/pull/1172 https://github.com/mandiant/capa-rules/pull/1173

In #1171, my proposal for discussion was ignored. In #1172, I explicitly stated I can PR the sample into testfiles before or after the discussion. This was seemingly ignored, as I was told to "address the linter" which pointed to the sample being missing - it was intentionally missing as I wanted discussion to go through first. In #1173, I was told to add a description field, which I did, which then led to the discovery of the description / namespace bug, and also I had to explain why the rules sat in nursery instead of the corresponding folders when capa's stance on rules have always been nursery-first.

I love capa but man whenever I want to submit new rules it's a stupid hassle.

0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 28, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
I managed to find a 6-year-old bug in capa whilst trying to make a new rule for detecting Windows Security Center related ops sometimes it really feels like capa is held together with duct tape and glue
0
1
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 27, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
I'm feeling pretty good about the shorts experiment from yesterday - I think it worked out well
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 26, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
Replying to @wessorh@infosec.exchange
@wessorh@infosec.exchange I get that you're trying to advertise your own Yara-related project, but please do not shove links down my comments every time when I wasn't actively looking for them. It was whatever when you were doing it once, but 3 times across platform is a bit much.
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 26, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
Why are antivirus so bad at catching malware? Let's talk detection engineering ❤️ https://twitch.tv/azakasekai 🤍 https://youtube.com/live/2ILs6q3q9TQ?feature=share
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 25, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
We’re nearly up to 30 episodes of REWorkshop, and I’ll be honest I still don’t know what viewers would like to see. Is there anything specifically you’d be interested in seeing?
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 21, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
the ability to preview arg names in line is so nice in IDA 9.4
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 20, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
a lot of people like to shit on AVs/EDRs for failing to detect or considering benign things to be malicious but man try doing it yourself detection engineering is hard
0
2
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 20, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
PC parts in current year no way
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 20, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange

Through StackTraceMetadata, we were able to rebuild the RVA to member mapping, so any .NET AoT compiled applications with StackTraceSupport on (the default) should be able to get its member names restored.

Other things that can help with reverse engineering:

  • Hydratable metadata/MethodTable/EEType should be present in either hydrated section or the .rdata section when hydration is off (.NET 8 = on; .NET 10 = off due to performance/memory savings). This is parsed by default from nativeaot IDA plugins.
  • Reflection data should theoretically contain the type, method, field names; this is on by default.

Things that will make our job annoying:

  • StackTraceSupport = off -> no RVA-member mapping -> biggest win against reverse engineers
  • reflectiondata = off -> no reflection-related data; this is not recommended because anything that relies on printing reflection information (e.g., exception names) will crash, and this option is gradually getting removed from .NET 10 and onwards.
  • MSVC linker is used during AoT compilation, so you can throw in additional linker args like bREPRO if you wanted to change the timestamp behavior, or NOCOFFGRPINFO if you don't want to keep POGO around.
  • DebuggerSupport = false -> minor but removes the DotNetRuntimeDebugHeader
  • NativeDebugSymbols = false -> removes PDB-related data
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 20, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
I finally found a nice way to crosspost now I can actually start posting across accounts like this again
0
0
0
0
Open post
still
安坂星海 Azaka || VTuber @still@infosec.exchange · Jul 15, 2026
安坂星海 Azaka || VTuber
@still@infosec.exchange

‧₊˚ ⋅ Indie Comfy VTuber ⊹˚. Employed Threat Intel Researcher ♡‧₊˚ SV Cover Artist ✧・゚https://azaka.fun *:・˚ @jamama_666 / @MomoiroKohi / @justNovaj / #artsyaz

infosec.exchange
ida.dll has been increasingly getting fatter and fatter. From the ~5MB of 8.4/9.1 to nearly 50+ MB in 9.4. I'm not really sure what Hex-Rays has been feeding IDA.
0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:35:55 UTC