//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
Profile
Loading...
Securing every bit of your data https://quarkslab.com
Quarkslab









Loading...
A hands-on look at Microsoft’s Independent Guest Virtual Machine (IGVM) format inside OpenHCL’s `openhcl.bin`. We unpack the fixed header, variable headers, data layout, and how IGVM measurement supports Confidential Computing with SEV-SNP and TDX. 🔗 blog.quarkslab.com/the-igvm-fil...
Practical Android Software Protection in the Wild: An Appetizer In which Eduardo Blazquez analyzes 2.5 million Android apps to identify and classify the obfuscators, packers and code protectors they use: blog.quarkslab.com/practical-an...
Obscure Element: Reverse engineering Xiaomi's MJA1 secure chip. Mengsi Wu's journey starts here: blog.quarkslab.com/black-box-pr...
Did you hear about Optical Line Terminals? ISPs rely on them to build their service networks, but what if they are vulnerable? Here Mathieu Farrell shows how attackers could compromise entire ISPs by exploiting them and cloud-based fleet management software blog.quarkslab.com/how-olts-may...
What happens when reverse engineers spend weeks poking at the Scala 3 codebase? 🔍 From code review to fuzzing, our assessment helped strengthen Scala's security. The results of our audit, conducted in collaboration with @ostifofficial.bsky.social, are here: blog.quarkslab.com/scala-securi...
BOLT is a static analysis tool, part of the LLVM compiler infrastructure, used to verify compiler security hardening options have been applied on a binary. Thanks to @ostifofficial.bsky.social we've worked since November 2025 to improve it. Check our progress here: blog.quarkslab.com/extending-ll...
Do you know how Entra ID applications work? What about the security mess they can bring and what they can quietly break? New blog post on Entra ID application permissions, the audit nightmare they create, and QAZPT, our OSS tool to actually make sense of it: blog.quarkslab.com/auditing-app...
Obfuscation vs The Optimizer: A Battle in LLVM Middle End. Robert Yates shows us how the continuous improvement of the LLVM optimizer defeats naive code obfuscation, and how the obfuscator can fight back. An eternal fight in which all victories are ephemeral blog.quarkslab.com/obfuscation-...
From prompt 😃to pwned 😢: Implementing an LLM in your org? Useful. Trusting its output? That's how a low-priv user became admin. Ship the feature, don't extend it your trust. blog.quarkslab.com/from-prompt-...
Paramiko is a pure-Python implementation of SSHv2. Recently, we worked with the Paramiko team on a security audit sponsored by @ostifofficial.bsky.social 🙏 Read a summary of our findings and find the full report here: blog.quarkslab.com/paramiko-sec...
1mo
18d
4d
1mo
21d
13d
1mo
2mo
17d
1mo
This article presents the structure of the Independent Guest Virtual Machine (IGVM) file format, a binary file designed to define and securely launch the initial state of a virtual machine. It bundles...
blog.quarkslab.com
The IGVM File Format - Quarkslab's blog
The Scala team has partnered with the Open Source Technology Improvement Fund (OSTIF) to conduct its first security audit. This initiative aims to identify potential vulnerabilities through static and...
blog.quarkslab.com
Scala Security Audit - Quarkslab's blog
The Open Source Technology Improvement Fund (OSTIF) commissioned Quarkslab to extend the BOLT-based static binary analyser in LLVM to support additional compiler flags for security hardening. This wor...
blog.quarkslab.com
Extending LLVM's BOLT-based Binary Analyser to Validate Stack Variable Initialisation - Quarkslab's blog
The OSTIF collaborated with Quarkslab to conduct a security audit of Paramiko, a pure-Python implementation of SSHv2 that provides both client- and server-side functionality. Given the sensitivity and...
blog.quarkslab.com
Paramiko Security Audit - Quarkslab's blog
Quarkslab
Quarkslab
Quarkslab
Quarkslab
Quarkslab
Quarkslab
Quarkslab
Quarkslab
Quarkslab
Quarkslab