Archives
- 08 Oct Lesson 1.5: Why LLMs cannot separate instructions from data
- 08 Oct Lesson 1.4: Tool calling, agents and MCP
- 08 Oct Lesson 1.3: Embeddings and RAG
- 08 Oct Lesson 1.2: Anatomy of a prompt
- 08 Oct Lesson 1.1: How an LLM works
- 08 Oct Lesson 0.4: Threat model of an LLM app
- 08 Oct Lesson 0.3: Building a safe lab with Ollama
- 08 Oct Lesson 0.2: Legal and ethical ground rules
- 08 Oct Lesson 0.1: What AI attacks are and how they differ
- 14 Dec M*CTF 2025: first place in Moscow
- 15 Nov CSCV 2025: second prize in Bracket B
- 21 Sep Digital Dragons 2025: a consolation prize in Da Nang
- 11 Jul HackTheon Sejong 2025: top 10 in Korea
- 19 Oct ASEAN Student Contest 2024: third prize in Attack-Defense
- 29 Aug Hunting NvidiaGraphicDriver.exe
- 20 Jun Analysing a malicious LNK shortcut
- 17 Dec Study materials and places to practice
- 09 Dec Reverse Engineering tool repository (roundup)
- 07 Dec Reverse Engineering technique repository (map)
- 30 Nov ASEAN Student Contest 2023: my first Attack-Defense final
- 22 Nov Cheatsheet: shortcuts and quick reference
- 20 Nov Lesson 20.3: Final project, reverse a program and write the report
- 08 Nov Lesson 20.2: Solving RE challenges in CTFs and writing a write-up
- 07 Nov Lesson 20.1: Hands-on with crackmes.one, level 1 to level 4
- 05 Nov Lesson 19.4: Extracting config and C2
- 27 Oct Lesson 19.3: Analyzing maldocs and loaders
- 22 Oct Lesson 19.2: IOC, YARA, capa and Sigma
- 17 Oct Lesson 19.1: A safe malware analysis workflow
- 14 Oct Lesson 18.8: AI-assisted reverse engineering
- 02 Oct PTIT CTF 2023: second prize at home
- 22 Sep Lesson 18.7: Reversing network protocols and proprietary file formats
- 13 Sep Keylogger and screenshot spyware
- 12 Sep Lesson 18.6: Reversing Windows drivers and Linux kernel modules
- 10 Sep Lesson 18.5: Reversing firmware and IoT devices
- 07 Sep Lesson 18.4: Binary diffing
- 04 Sep Lesson 18.3: Symbolic execution
- 01 Sep Lesson 18.2: Emulation, running a piece of code on its own
- 25 Aug Lesson 18.1: Scripting the decompiler
- 14 Aug Lesson 17.7: Dynamic Binary Instrumentation
- 08 Aug Lesson 17.6: LD_PRELOAD, ptrace and DYLD_INSERT_LIBRARIES
- 07 Aug Lesson 17.5: Recognizing process injection in malware
- 03 Aug Lesson 17.4: Recognizing DLL injection techniques
- 29 Jul Lesson 17.3: Hooking on Windows, IAT hooks and inline hooks
- 29 Jul Reading list: the books behind these notes
- 19 Jul Lesson 17.2: Frida, inspecting and modifying a running program
- 15 Jul Lesson 17.1: Patching binaries
- 14 Jul Lesson 16.4: Rewriting the algorithm in Python and solving with Z3
- 05 Jul Lesson 16.3: Recognizing AES, DES, TEA, ChaCha and hash functions
- 03 Jul Lesson 16.1: Identifying crypto algorithms by their constants
- 03 Jul Lesson 16.2: XOR, RC4 and custom Base64
- 01 Jul Lesson 15.10: Handling stacked anti-analysis layers
- 22 Jun Lesson 15.9: Bypassing anti-debug
- 21 Jun Lesson 15.8: Integrity checks and anti-tamper
- 21 Jun Lesson 15.7: Anti-attach, anti-dump and anti-hook
- 09 Jun Lesson 15.6: Anti-disassembly
- 23 May Lesson 15.5: Anti-VM and anti-sandbox
- 20 May Lesson 15.4: Advanced anti-debug, self-debug and TLS callbacks
- 12 May Lesson 15.3: Anti-debug group 3, timing and traps
- 09 May Lesson 15.2: Anti-debug by reading the PEB
- 07 May Lesson 15.1: Anti-debug via Windows APIs
- 06 May Lesson 14.6: Automatic deobfuscation
- 03 May Lesson 14.5: Code virtualization
- 30 Apr Lesson 14.4: Code-level obfuscation
- 18 Apr Lesson 14.3: Dumping a process and rebuilding the IAT with Scylla
- 11 Apr Lesson 14.2: Unpacking UPX, automatic and manual
- 04 Apr Lesson 14.1: How packers work and how to spot one
- 03 Apr Lesson 13.5: Cheat Engine and runtime memory
- 01 Apr Lesson 13.4: Lua and LuaJIT bytecode
- 29 Mar Lesson 13.3: Reversing Unreal Engine games
- 26 Mar Lesson 13.2: Unity IL2CPP
- 06 Mar Lesson 13.1: Unity with the Mono backend
- 14 Feb Lesson 12.3: Reversing an iOS app from the IPA file
- 03 Feb Lesson 12.2: Swift reverse engineering
- 01 Feb Lesson 12.1: Objective-C and objc_msgSend
- 29 Jan Lesson 11.3: WebAssembly
- 27 Jan Lesson 11.2: Dissecting an Electron app
- 21 Jan Lesson 11.1: Deobfuscating JavaScript
- 13 Jan Lesson 10.3: Scripts packed into exes
- 30 Dec Lesson 10.2: Visual Basic 6
- 28 Dec Lesson 10.1: Reversing Delphi and C++Builder programs
- 18 Dec Lesson 9.3: Rust crackme lab
- 03 Dec Lesson 9.2: Rust's String, Vec, iterators and trait objects
- 30 Nov Lesson 9.1: What Rust binaries look like
- 19 Nov Lesson 8.4: Lab, solving a Go crackme
- 19 Nov Lesson 8.3: Go's string, slice, interface and goroutine in assembly
- 18 Nov Lesson 8.2: Recovering function names and types in Go binaries
- 15 Nov Lesson 8.1: What Go binaries look like
- 14 Nov Lesson 7.6: Lab, decompiling sample .pyc files with pycdc
- 13 Nov Lesson 7.5: Nuitka, Cython and PyArmor
- 12 Nov Lesson 7.4: Python packaged as an .exe
- 05 Nov Lesson 7.3: Python decompilers other than pycdc
- 04 Nov Lesson 7.2: pycdc and pycdas
- 01 Nov Lesson 7.1: Python bytecode and .pyc files
- 30 Oct Lesson 6.9: Big lab, solving OWASP UnCrackable Level 1 to 3
- 29 Oct Lesson 6.8: Obfuscation and packers on Android
- 24 Oct Lesson 6.7: Native .so libraries and JNI
- 21 Oct Lesson 6.6: Frida on Android
- 20 Oct Lesson 6.5: Kotlin in bytecode
- 13 Oct Lesson 6.4: Smali and apktool, patching and repacking an Android app
- 27 Sep Lesson 6.3: JADX-GUI in depth
- 26 Sep Lesson 6.2: Anatomy of an APK file
- 01 Sep Lesson 6.1: JVM bytecode and Java decompilers
- 30 Aug PTIT CTF 2022: my first CTF prize
- 26 Aug Lesson 5.7: Combined lab, solving .NET crackmes
- 22 Aug Lesson 5.6: Modern .NET publish modes
- 21 Aug Lesson 5.5: .NET obfuscators and how to strip them
- 17 Aug Lesson 5.4: Editing a .NET assembly and saving it
- 16 Aug Lesson 5.3: Debugging .NET without source using dnSpy
- 06 Aug Lesson 5.2: ILSpy and dnSpy
- 31 Jul Lesson 5.1: .NET internals
- 24 Jul Lesson 4.6: Lab, a C++ crackme with a vtable
- 20 Jul Lesson 4.5: Plugins that rebuild C++ classes
- 16 Jul Lesson 4.4: Exceptions, templates and lambdas
- 10 Jul Lesson 4.3: STL in binaries, std::string and std::vector
- 29 Jun Lesson 4.2: Classes, vtables, inheritance and RTTI
- 21 Jun Lesson 4.1: C++ for reversers, name mangling and the this pointer
- 14 Jun Lesson 3.6: Writing a keygen
- 10 Jun Lesson 3.5: Lab, solving your first C crackme
- 08 Jun Lesson 3.4: FLIRT and recognizing library functions
- 05 Jun Lesson 3.3: Structs in assembly and how to recover them
- 28 May Lesson 3.2: Variables, pointers, arrays and strings in assembly
- 22 May Lesson 3.1: Hello world and finding the real main
- 20 May Lesson 2.8: System monitoring
- 19 May Lesson 2.7: Hex editors and templates
- 09 May Lesson 2.6: GDB, pwndbg and WinDbg
- 03 May Lesson 2.5: x64dbg basics
- 22 Apr Lesson 2.4: Binary Ninja, Cutter and radare2
- 13 Apr Lesson 2.3: Ghidra basics
- 12 Apr Lesson 2.2: IDA for beginners
- 10 Apr Lesson 2.1: Five-minute triage with DIE, strings and PE-bear
- 10 Apr Lesson 1.13: Recognizing Windows APIs when reversing
- 01 Apr Lesson 1.12: Windows internals for RE (3): SEH, TLS callbacks and syscalls
- 26 Mar Lesson 1.10: Windows internals (1), Win32 API and DLLs
- 26 Mar Lesson 1.11: Windows internals (2), PEB, TEB, handles and tokens
- 23 Mar Lesson 1.9: ARM/ARM64 basics for people who know x86
- 21 Mar Lesson 1.8: ELF and Mach-O
- 16 Mar Lesson 1.7: The PE format
- 01 Mar Lesson 1.6: From source code to binary
- 28 Feb Lesson 1.5: x86/x64 Assembly (3), if, loops, switch, arrays and structs
- 26 Feb Lesson 1.4: x86/x64 assembly (2), stack frames and calling conventions
- 22 Feb Lesson 1.3: x86/x64 Assembly (1), registers and common instructions
- 18 Feb Lesson 1.2: Process memory map
- 05 Feb Lesson 1.1: Reading a hexdump like text
- 01 Feb Lesson 0.4: The reverse engineering workflow
- 29 Jan Lesson 0.3: Setting up a safe lab
- 19 Jan Lesson 0.2: Legal and ethics
- 11 Jan Lesson 0.1: What is reverse engineering