corpus.blog
Most cited
Talked about
Blogs
54,302 blogs · [ { "id": "01a0c769-f5e1-717d-98d4-caed9823f2be", "title": "Threat Risk Assessment Tool (Arcg)", "url": "https://defense.sh//res/tm/architect/riskcalc.html", "published_at": "2026-08-16T07:51:59+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed9861626a", "title": "Threat Risk Assessment Tool (Dev)", "url": "https://defense.sh//res/tm/developer/riskcalc.html", "published_at": "2026-08-16T07:51:59+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a15cbb746d", "title": "afd5856c26183402eae…", "url": "https://defense.sh//exploiting/2026/08/06/paper.html", "published_at": "2026-08-06T00:00:00+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a15d55ce1b", "title": "Building for chaos - Self-Healing TPM State", "url": "https://defense.sh//tpm/2026/02/05/tpm-compute-auth-digest.html", "published_at": "2026-02-05T00:00:00+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a15d88d78c", "title": "Linux Kernel Vulnerability Lurking for ~20 Years", "url": "https://defense.sh//tpm/exploiting/unix/kernel/2025/10/04/tpm-inf-recv.html", "published_at": "2025-10-04T00:00:00+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a15e4694be", "title": "Bell-LaPadula Model has a covert channel and nobody talks about it!", "url": "https://defense.sh//unix/sec-process/2025/09/11/blp-covert.html", "published_at": "2025-09-11T00:00:00+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a15eb47160", "title": "dTPM is dead", "url": "https://defense.sh//tpm/2025/09/10/dtpm-is-dead.html", "published_at": "2025-09-10T00:00:00+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a15f9f6974", "title": "Point is not on the required curve!", "url": "https://defense.sh//tpm/2025/09/03/point-not-on-curve.html", "published_at": "2025-09-03T00:00:00+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a15fe7fd06", "title": "TPM Fault Injection", "url": "https://defense.sh//tpm/2025/09/03/tpm-fault-injection.html", "published_at": "2025-09-03T00:00:00+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a160c8d137", "title": "A Methodology for Security Requirement Engineering", "url": "https://defense.sh//sec-process/2025/04/04/sre.html", "published_at": "2025-04-04T00:00:00+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a1614740d5", "title": "Preemptive scheduling on 16-bit real-mode os?", "url": "https://defense.sh//os/2022/09/27/rm-sched.html", "published_at": "2022-09-27T00:00:00+00:00" }, { "id": "01a0876a-d322-70b5-ba20-a2a16153b296", "title": "Algorithm for Constructing Grammar Graph (Fuzzing)", "url": "https://defense.sh//fuzzing/2022/05/24/gram-graph.html", "published_at": "2022-05-24T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed9060d9d0", "title": "Authorization on Linux local IPC using SO_PEERCRED", "url": "https://defense.sh//unix/2022/05/21/local-ipc-auth.html", "published_at": "2022-05-21T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed905142ab", "title": "Rethinking SETUID root, Historical Approaches to Least Privilege", "url": "https://defense.sh//unix/caps/2022/02/01/route-to-no-root.html", "published_at": "2022-02-01T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8f6d9aa9", "title": "Why setgid to nobody?", "url": "https://defense.sh//unix/2021/12/17/setgid-to-nobody.html", "published_at": "2021-12-17T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8e88c824", "title": "The Confused Deputy and Capability Systems", "url": "https://defense.sh//unix/caps/2021/11/22/confused-deputy.html", "published_at": "2021-11-22T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8e1bdbe8", "title": "What is PR_SET_CHILD_SUBREAPER, How is it related to double-forked daemon?", "url": "https://defense.sh//unix/2021/11/17/double-forked-daemon.html", "published_at": "2021-11-17T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8dc2e66f", "title": "Optimizing LibFuzzer Mutator Selection with Multi-Armed Bandits", "url": "https://defense.sh//fuzzing/2019/11/11/libfuzzer-mab.html", "published_at": "2019-11-11T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8d236c95", "title": "Reducing Code Coverage Overhead using “Disposable Probes” (Fuzzing)", "url": "https://defense.sh//oldblog/fuzzing/2018/03/21/disposable-probes.html", "published_at": "2018-03-21T13:26:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8c312abb", "title": "Improving Coverage Guided Fuzzing Using Simple Static Analysis", "url": "https://defense.sh//oldblog/fuzzing/2017/05/01/improving-coverage-guided-fuzzing-using-static-analysis.html", "published_at": "2017-05-01T15:36:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8b6e5707", "title": "Fuzzing and Instrumenting Windows Kernel", "url": "https://defense.sh//oldblog/fuzzing/kernel/2017/04/27/kfuzz-a-fuzzer-story.html", "published_at": "2017-04-27T14:18:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8b0824ad", "title": "Write up for Iranian Society of Cryptology CTF", "url": "https://defense.sh//oldblog/re/2015/09/08/blood-money.html", "published_at": "2015-09-08T10:51:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8a61b3ef", "title": "Text Steganography In Farsi/Arabic Language", "url": "https://defense.sh//exploiting/2015/02/01/farsi-text-steg.html", "published_at": "2015-02-01T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8a2c28d7", "title": "Multiple Vulnerabilities in Padvish Antivirus Kernel Driver", "url": "https://defense.sh//exploiting/kernel/2014/09/27/padvish-av.html", "published_at": "2014-09-27T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed8a071aed", "title": "Noroi - Polymorphic Decoder Generator for Shellcodes", "url": "https://defense.sh//exploiting/re/2014/03/26/noroi-polymorphic-decoder.html", "published_at": "2014-03-26T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed89fa8062", "title": "Defeating Windows Kernel Driver Singing Enforcement", "url": "https://defense.sh//oldblog/exploiting/2012/11/04/bypassing-driver-singing-not-that-much-hard.html", "published_at": "2012-11-04T12:51:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed89a8fdc9", "title": "Introducing Pwnypot - Deteting Drive-By-Download Zerodays", "url": "https://defense.sh//oldblog/exploiting/2012/09/25/introducing-mcedp-honeyclient.html", "published_at": "2012-09-25T23:54:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed88e56597", "title": "Exploting Windows Kernel/Intel x64 SYSRET Vulnerability", "url": "https://defense.sh//oldblog/exploiting/kernel/2012/08/25/windows-kernel-intel-x64-sysret-vulnerability-code-signing-bypass-bonus.html", "published_at": "2012-08-25T23:28:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed880bb240", "title": "Bypassing Award-Winning ($50k) EMET 3.5’s ROP Mitigations", "url": "https://defense.sh//oldblog/exploiting/2012/08/08/bypassing-emet-3-5s-rop-mitigations.html", "published_at": "2012-08-08T00:00:00+00:00" }, { "id": "01a0c769-f5e1-717d-98d4-caed95520f6d", "title": null, "url": "https://defense.sh//about/", "published_at": null }, { "id": "01a0c769-f5e1-717d-98d4-caed96207e9a", "title": "Shahriyar Jalayeri Blog", "url": "https://defense.sh//blog/", "published_at": null }, { "id": "01a0c769-f5e1-717d-98d4-caed96e6cef9", "title": null, "url": "https://defense.sh//categories/", "published_at": null }, { "id": "01a0c769-f5e1-717d-98d4-caed97151b5a", "title": "Shahriyar Jalayeri - Security Consultant", "url": "https://defense.sh//", "published_at": null }, { "id": "01a0c769-f5e1-717d-98d4-caed97f3e989", "title": null, "url": "https://defense.sh//resources/", "published_at": null } ] posts
Claim your blog
Back to defense.sh
Blog · corpus.blog/blogs/defense.sh/posts
defense.sh
defense.sh
2026
Threat Risk Assessment Tool (Arcg)
original ↗
16 Aug 2026
Threat Risk Assessment Tool (Dev)
original ↗
16 Aug 2026
afd5856c26183402eae…
original ↗
6 Aug 2026
Building for chaos - Self-Healing TPM State
original ↗
5 Feb 2026
2025
Linux Kernel Vulnerability Lurking for ~20 Years
original ↗
4 Oct 2025
Bell-LaPadula Model has a covert channel and nobody talks about it!
original ↗
11 Sept 2025
dTPM is dead
original ↗
10 Sept 2025
Point is not on the required curve!
original ↗
3 Sept 2025
TPM Fault Injection
original ↗
3 Sept 2025
A Methodology for Security Requirement Engineering
original ↗
4 Apr 2025
2022
Preemptive scheduling on 16-bit real-mode os?
original ↗
27 Sept 2022
Algorithm for Constructing Grammar Graph (Fuzzing)
original ↗
24 May 2022
Authorization on Linux local IPC using SO_PEERCRED
original ↗
21 May 2022
Rethinking SETUID root, Historical Approaches to Least Privilege
original ↗
1 Feb 2022
2021
Why setgid to nobody?
original ↗
17 Dec 2021
The Confused Deputy and Capability Systems
original ↗
22 Nov 2021
What is PR_SET_CHILD_SUBREAPER, How is it related to double-forked daemon?
original ↗
17 Nov 2021
2019
Optimizing LibFuzzer Mutator Selection with Multi-Armed Bandits
original ↗
11 Nov 2019
2018
Reducing Code Coverage Overhead using “Disposable Probes” (Fuzzing)
original ↗
21 Mar 2018
2017
Improving Coverage Guided Fuzzing Using Simple Static Analysis
original ↗
1 May 2017
Fuzzing and Instrumenting Windows Kernel
original ↗
27 Apr 2017
2015
Write up for Iranian Society of Cryptology CTF
original ↗
8 Sept 2015
Text Steganography In Farsi/Arabic Language
original ↗
1 Feb 2015
2014
Multiple Vulnerabilities in Padvish Antivirus Kernel Driver
original ↗
27 Sept 2014
Noroi - Polymorphic Decoder Generator for Shellcodes
original ↗
26 Mar 2014
2012
Defeating Windows Kernel Driver Singing Enforcement
original ↗
4 Nov 2012
Introducing Pwnypot - Deteting Drive-By-Download Zerodays
original ↗
25 Sept 2012
Exploting Windows Kernel/Intel x64 SYSRET Vulnerability
original ↗
25 Aug 2012
Bypassing Award-Winning ($50k) EMET 3.5’s ROP Mitigations
original ↗
8 Aug 2012
Undated
https://defense.sh//about/
original ↗
—
Shahriyar Jalayeri Blog
original ↗
—
https://defense.sh//categories/
original ↗
—
Shahriyar Jalayeri - Security Consultant
original ↗
—
https://defense.sh//resources/
original ↗
—