Matt Ehrnschwender's Avatar

Matt Ehrnschwender

@cybershenanigans.space

Security person who likes writing code

40
Followers
45
Following
11
Posts
11.11.2024
Joined
Posts Following

Latest posts by Matt Ehrnschwender @cybershenanigans.space

Preview
Release Boflink v0.6.1 ยท MEhrn00/boflink 0.6.1 - 2026-01-22 Fixed Panic at src/graph/output.rs:607 that would trigger if the size of the output .bss section was larger than the total size of the output file. (#38) CI built release binari...

Pushed up a few small fixes for boflink. Currently working on some other improvements which should make writing BOFs in higher level languages like C++/Rust/Zig a lot more feasible without needing to add various different compiler/source code tricks github.com/MEhrn00/bofl...

22.01.2026 18:47 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

With everyone publishing information on every corner of the Internet, it's never easy to stay informed

29.11.2025 18:32 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

There are some rather ...interesting... opsec and design decisions in there but the core of it is that each component is split up and designed to run in a separate process using a main "orchestrator" for managing IPC. The posts above are good reads to help spark some ideas

29.11.2025 06:41 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Analysis of the CloudWizard APT framework Kaspersky analysis of the CloudWizard APT framework used in a campaign in the region of the Russo-Ukrainian conflict.

Three samples that come to mind are CloudWizard securelist.com/cloudwizard-..., CloudSorcerer securelist.com/cloudsorcere... and Deadglyph www.welivesecurity.com/en/eset-rese.... They more or less do this where each module is spread across multiple different processes

29.11.2025 06:41 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
GitHub - MEhrn00/boflink: Linker for Beacon Object Files Linker for Beacon Object Files. Contribute to MEhrn00/boflink development by creating an account on GitHub.

Finally releasing a project publicly I have been pretty excited about. Here is Boflink, a linker for Beacon Object Files. github.com/MEhrn00/bofl...

Supporting blog post about it. blog.cybershenanigans.space/posts/boflin...

30.05.2025 20:18 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Windows OpenSSH agent will store SSH keys under "HKCU:Software\OpenSSH\Agent\Keys". It's on my TODO list to write a tool that will extract these and decrypt them if needed

10.04.2025 22:00 ๐Ÿ‘ 7 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image Post image

First: Visual Studio Code

Visual Studio Code stores it's cached tabs at %APPDATA%\Code\Backups\<guid>\

The untitled temporary tabs will be found in the untitled folder, and each file contains the contents of those tabs

08.04.2025 16:16 ๐Ÿ‘ 7 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Not sexy things, but they make my day-to-day usage much better. I've seen many people bemoan about Ghidra 's interface. My experience with ANY tool is that things don't change unless the problem is reported to the devs. So reach out and lay out your concerns - they'll respond!

07.02.2025 21:00 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Embedding Files in C/C++ Programs Background Recently, I came across a post on X by @0xTriboulet asking how to deal with large header files in Visual Studio projects https://x.com/0xTriboulet/status/1878139439714558169. intelligence i...

This is a pretty handy trick that I don't commonly see people doing. It's possible to embed a large file in a C/C++ program without needing to create a giant header file for it. Here's a slightly (...very) detailed blog post on it blog.cybershenanigans.space/posts/embedd...

13.01.2025 23:30 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Where do I subscribe?

09.01.2025 17:54 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

๐Ÿ”ฅ๐Ÿ”ฅ๐Ÿ”ฅ

04.12.2024 19:02 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Giving Advent of Code 2024 a go, first time using Rust so makes a nice challenge while learning something new D

01.12.2024 19:18 ๐Ÿ‘ 15 ๐Ÿ” 1 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 0
Preview
a woman wearing glasses says please with her hand up ALT: a woman wearing glasses says please with her hand up

It's that time of year again everybody! I want to know YOUR thoughts on Mythic! What did you like? What could be improved? What would you like to see next? Why do you or don't you use it? If you could change something, what would it be? www.surveymonkey.com/r/MythicPlan... I'm all ears :)

25.11.2024 17:35 ๐Ÿ‘ 10 ๐Ÿ” 5 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 2
Post image

Look, I get it. We've normalized running ads in search results for companies to try to make more money. But I really don't need an ad for buying "linux kernel modules" on Amazon ๐Ÿคฆ

22.11.2024 21:36 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

you want a patchless amsi bypass?

21.11.2024 16:54 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Writing Beacon Object Files Without DFR Intro Beacon Object Files have become very popular for red teams to add additional capabilities on the fly without needing to include the overhead of a reflective DLL or .NET assembly. This advantage ...

Since this is turning into the the infosec social media platform, I've been working on trying to keep up with my security/technical related blog. I just released a new blog post: "Writing Beacon Object Files Without DFR" blog.cybershenanigans.space/posts/writin...

18.11.2024 20:37 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0