RSSAmplifier

Blog

Engineering Deficiency @ Meekolabs

Shitposts disguised as thinly-veiled attempts at security research on Windows Kernel Exploitation, Cloud Security, Machine Learning, and other random topics

research.meekolab.comRSS feed ↗20 posts

Latest posts

Forensics on Network Appliances

This research was done using hardware obtained by myself individually, analyzed using hardware owned by myself individually. Information and opinions held in this presentation are my own and do not reflect my current or previous employers Cover Illus...

Messing Around with GPUs Again

Cover Illustration by atomic_arctic While doing matrixes on GPUs are kind of overplayed, they still represent one of the most important computation for modern AI workloads, making up the vast majority of FLOPS during both training and inference of d...

Deepseek's Low Level Hardware Magic

Cover Illustration by onigiriice There has been alot of copium about Deepseek-R1 leapfrogging ChatGPT-o1 in benchmarks, with many accusing Deepseek either lying about their capabilities or sanction-busting US export controls. Moreover, the whole pan...

The Elusive Apple Matrix Coprocessor (AMX)

Cover Illustration by ochxzuke I was heading for a trip over the weekends where i would be far from my main workstation, and at this time i was looking to continue my current run of Persona 5 Royal on the PC. Recently with the launch of MacOS Sonoma...

Behind Chrome-Based DLP Plugins

Cover Illustration by buruberrii_ While we discussed previously about how endpoint-based DLP/EDR agents work in macOS, there is another component of endpoint security systems that are often overlooked and that is the browser extension component. End...

Peeking Inside Apple's Private Cloud Compute

Cover Illustration by onigiriice——————————————————————————————————————— The article contains partial content similar to Matteyeux’s article on the PCC VRE, for more observations about the firmware and its debuggability see the article here During th...

Mitigating DMA Attacks Through Redirected Address Tables

Cover Illustration by buruberrii_ In a previous blog post, i talk briefly about the many methods on how anticheat systems like Vanguard protect against different type of cheating attempts. One of the methods discussed was the detection of malicious ...

Smuggling Malware Using HoYoverse Games

Cover Illustration by ireneparamithaa Hoyoverse, the studio behind some of the most popular games in recent years, has increasingly found itself in the crosshairs of cybercriminals and threat actors. With the company recently securing the title of "...

The Basics of Intel VT-x Extensions

Cover Illustration by t0meku Traditionally, x86 processors lacked built-in virtualization support, leading to significant challenges when implementing efficient Virtual Machine Monitors (VMMs) or hypervisors. But then Intel made Intel VT as a hardwa...

Understanding Kernel-Level Anticheats in Online Games

Cover Illustration by atomic_arctic This research was done using software obtained by myself individually or through open-source projects abiding to all licenses. There is no intention of harming any company’s product. This post is not meant to be a...

Quick Analysis About the Crowdstrike Situation

Cover Illustration by ireneparamithaa DISCLAIMER : This research was done using software obtained by myself individually, analyzed using hardware owned by myself individually. Some code may be simplified and edited to provide clarity or to maintain ...

Exploring the Power of Parallelized CPU Architectures

Cover Illustration by hi__dan In a recent trip from Japan, i came to score a rare PS3 reference tool (DECR-1000J) which was sold below market rates. As these things are apparently very rare and are not regionlocked unlike the retail models, i took t...

Dissecting the xz-utils Backdoor

Cover Illustration by cloudnienty On March 29th, 2024, a critical backdoor (CVE-2024-3094) was discovered in the widely-used xz/liblzma package, a program for interacting with lzma-based compressed files. The backdoor was discovered by a Microsoft e...

Internals of macOS Endpoint Security Products

Cover Illustration by cloudnienty This research was done using software obtained by myself individually, analyzed using hardware owned by myself individually. Some code is simplified and edited to provide clarity. The article is not intended to harm...

Introduction to the Apple Endpoint Security Framework

Cover Illustration by ireneparamithaa For years there are two camps of perception in MacOS security, those who think that Macs are impenetrable boxes by design and sysadmins who are constantly horrified by the lack of protections that MacOS has desp...

A Shitty FLARE-On 10 Writeup for Challenge 4 (Aimbot)

Cover Illustration by mocapoca_, the illustration is purchasable via https://twitter.com/mocapoca_/status/1728761352469324072 (Indonesian only) This is a write up of FLARE-ON Challenge 4, which is unfortunately where I stopped doing the challenges d...

Second Guessing the MGM-Okta Hack

Cover Illustration by mocapoca_ A lot of fuzz has been made about the ALPHV/Blackcat hack against MGM Resorts, where they said that they exploited MGM's Okta Agent to sniff for passwords, gaining super administrator privileges to MGM's Okta account ...

Recreating the RAMP Forum EDR Bypass

Cover Illustration by mocapoca_ Last month, a guy named spyboy began advertising an EDR evasion tool for the Windows operating system via the Russian-language forum RAMP. The author claims that the software, called “Terminator”, can bypass leading E...

Evading EDRs by Unhooking NTDLL In-Memory

EDR (Endpoint Detection and Response) hooking is a well-known technique used in cybersecurity, and there are many examples available online of unhooking NTDLL (NT Dynamic Link Library), often using direct syscalls or mapping of NTDLL from disk or kno...

Detecting Amateur CobaltStrike Operators

CobaltStrike by HelpSystems is an adversary simulation tool with advanced attack and evasion strategies. While its use have gained popularity within red teams, its abuse has also been increasing with threat actors. CobaltStrike is used by sophisticat...