<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Cyberus Technology Blog</title>
        <link>https://www.cyberus-technology.de/blog.html</link>
        <description></description>
        <lastBuildDate>Thu, 10 Jun 2021 06:48:23 GMT</lastBuildDate>
        <docs>http://blogs.law.harvard.edu/tech/rss</docs>
        <generator>CT-GENv1</generator>
        <image>
            <title>Cyberus Technology Blog</title>
            <url>https://www.cyberus-technology.de/assets/images/bloglist_background_cyberus.jpg</url>
            <link>https://www.cyberus-technology.de/blog.html</link>
        </image>
        <copyright>All rights reserved by Cyberus Technology GmbH</copyright>
        <atom:link href="https://www.cyberus-technology.de/atom.xml" rel="self" type="application/rss+xml"/>
        <item>
            <title><![CDATA[Cyberus Secure Virtualization Platform: A technical perspective]]></title>
            <link>https://www.cyberus-technology.de/posts/2021-05-19-svp-tech-deep-dive.html</link>
            <guid>https://www.cyberus-technology.de/posts/2021-05-19-svp-tech-deep-dive.html</guid>
            <pubDate>Tue, 18 May 2021 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>In the <a href="/posts/2021-01-27-svp.html">last post of this series</a>, we described the value proposition of the Cyberus Secure Virtualization Platform (SVP). This post goes into more technical details.</p>
<p>In this post we will talk about:</p>
<ul>
<li>SVP as a fast, flexible and secure virtualization platform.</li>
<li>How the open-source <a href="/posts/2020-11-13-hedron-hypervisor.html">Hedron Hypervisor</a> enables uniquely flexible virtualization solutions</li>
<li>How our microkernel-based virtualization stack enables a small Trusted Compute Base for high-security use-cases</li>
<li>Enabling great performance through pass-through virtualization</li>
</ul>
<figure>
<img src="/assets/images/istock-514003464-1200.jpg" alt="SVP is flexible and secure" /><figcaption aria-hidden="true">SVP is flexible and secure</figcaption>
</figure>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Cyberus Technology Gives Keynote at Symposium on the Science of Security (HotSoS)]]></title>
            <link>https://www.cyberus-technology.de/posts/2021-04-09-hotsos-keynote.html</link>
            <guid>https://www.cyberus-technology.de/posts/2021-04-09-hotsos-keynote.html</guid>
            <pubDate>Thu, 08 Apr 2021 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p><a href="https://cps-vo.org/group/hotsos">HoTSoS</a> identifies itself as “research event centered on the Science of Security, which aims to address the fundamental problems of security in a principled manner.” Because the seminal <a href="https://spectreattack.com/spectre.pdf">Spectre paper</a> won NSA’s <a href="https://cps-vo.org/node/72248">Best Scientific Cybersecurity Paper Competition</a> last year, its authors were invited to give a keynote speech at the symposium. Given that the corresponding vulnerabilities were disclosed to Intel almost 4 years ago, we (the authors) decided to take a step back and to look, in HotSoS’ spirit, at the fundamental problems. We (Cyberus Technology) feel deeply honoured that we were entrusted with delivering the talk and want to give you a sneak preview of what to expect.</p>
<ul>
<li>Iron Law of processor performance</li>
<li>Memory latency, caching, and side-channels</li>
<li>Turing machine and performance increase through parallelism</li>
<li>Control flow discontinuities: branch history (BHT) and branch targets (BTB)</li>
<li>Spectre v1 (BHT) and v2 (BTB)</li>
</ul>
<p>By the way, the conference is fully virtual this year and <a href="https://cps-vo.org/group/hotsos/registration">registration</a> is open to everybody for free. The keynote is scheduled for April 14th, 15:35 CEST (9:35am EDT).</p>
<p>Update: in case you are curious about the keynote, the organisers made the <a href="https://cps-vo.org/node/74247">slides and the recording</a> available on the HoTSoS site. You can also go directly to <a href="https://www.youtube.com/watch?v=MZFCfj6bxgc">YouTube</a> to watch the video.</p>
<figure>
<img src="/assets/images/hotsos-title.png" alt="Cyberus Technology keynote @ 2021 HoTSoS symposium" /><figcaption aria-hidden="true">Cyberus Technology keynote @ 2021 HoTSoS symposium</figcaption>
</figure>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Cyberus Technology Presents new Perspectives on Virtual Machine Introspection at Biggest German IT Security Congress]]></title>
            <link>https://www.cyberus-technology.de/posts/2021-02-08-sicherheitskongress.html</link>
            <guid>https://www.cyberus-technology.de/posts/2021-02-08-sicherheitskongress.html</guid>
            <pubDate>Sun, 07 Feb 2021 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>The <a href="https://www.ubivent.com/register/bsi-it-sicherheitskongress-2021">17th German IT-Security Congress</a>, organized by the <a href="https://www.bsi.bund.de">Federal Office for Information Security (BSI)</a>, took place on February 2/3 and Cyberus Technology was among a select group of companies providing insights into new developments in this field. Given we are probably best known for our secure virtualization platform (SVP), we used the opportunity to highlight security-related use cases beyond virtualization’s isolation properties. Starting point were the recent <a href="https://www.sans.org/blog/what-you-need-to-know-about-the-solarwinds-supply-chain-attack/">Solarwinds-related security incidents</a> that highlight the need for more checks and balances in current computer systems. How can we limit the consequences of compromised software, even when a trusted system component is affected? We presented <a href="https://en.wikipedia.org/wiki/Virtual_machine_introspection">Virtual Machine Introspection</a> as game changing answer and talked about its basic principles in laymen’s terms. In the following you will find a condensed version of our talk.</p>
<figure>
<img src="/assets/images/17sicherheitskongress_intro.png" alt="Cyberus Technology @ 17. Dt. IT-Sicherheitskongress" /><figcaption aria-hidden="true">Cyberus Technology @ 17. Dt. IT-Sicherheitskongress</figcaption>
</figure>
<p>Key Points:</p>
<ul>
<li>Compromised software of the trusted compute base is a major challenge as it allows attackers to fly under the radar</li>
<li>VMI provides for defense-in-depth and enables event-driven response in a sandbox environment</li>
<li>Our microkernel-based architecture offers fine-grained access rights managements, thus limiting the consequences of vulnerabilities</li>
</ul>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[General Availability of Cyberus Secure Virtualization Platform]]></title>
            <link>https://www.cyberus-technology.de/posts/2021-01-27-svp.html</link>
            <guid>https://www.cyberus-technology.de/posts/2021-01-27-svp.html</guid>
            <pubDate>Tue, 26 Jan 2021 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>Today Cyberus Technology announces the general availabiliy of SVP, a fast, flexible and secure virtualization platform. SVP is a fully vertically integrated virtualization solution, designed to enable our customers’ use-cases with high performance and increased security.</p>
<p><a href="https://www.secunet.com">secunet</a> has adopted our fast and flexible Secure Virtualization Platform, SVP, as the base platform of SINA Workstation <a href="#read-more">⁴</a>. SINA Workstation is a secure workstation designed for modern working in Public Administration.</p>
<p>Key Points:</p>
<ul>
<li>General availability of SVP, a fast, flexible and secure virtualization platform</li>
<li>SVP drives the next generation of SINA Workstation, a secure workstation designed for the public sector</li>
<li>A microkernel-based architecture offers the flexibility to tailor the platform to a wide variety of use-cases</li>
<li>Support for GPU virtualization enables performant video conferences and improves battery life</li>
</ul>
<figure>
<img src="/assets/images/istock-514003464-1200.jpg" alt="SVP is flexible and secure" /><figcaption aria-hidden="true">SVP is flexible and secure</figcaption>
</figure>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Introducing the Hedron Hypervisor]]></title>
            <link>https://www.cyberus-technology.de/posts/2020-11-13-hedron-hypervisor.html</link>
            <guid>https://www.cyberus-technology.de/posts/2020-11-13-hedron-hypervisor.html</guid>
            <pubDate>Thu, 12 Nov 2020 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>At Cyberus Technology we work on a fast, flexible and secure compute environment. Our innovative virtualization stack is an integral part of this strategy. The foundation of this stack is the open-source <a href="https://github.com/cyberus-technology/hedron">Hedron Hypervisor</a>. Hedron already drives our malware analysis platform <a href="https://www.cyberus-technology.de/products/tycho.html">Tycho</a> and will soon be at the heart of a high-security workstation solution.</p>
<p>This blog post introduces the Hedron Hypervisor and philosophy around it.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[TCP Connection Analysis with Tycho]]></title>
            <link>https://www.cyberus-technology.de/posts/2020-08-28-network-analysis-with-tycho.html</link>
            <guid>https://www.cyberus-technology.de/posts/2020-08-28-network-analysis-with-tycho.html</guid>
            <pubDate>Thu, 27 Aug 2020 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>Network analysis is an important and interesting part of malware analysis. Very often malware communicates with so-called <a href="https://www.trendmicro.com/vinfo/us/security/definition/command-and-control-server"><strong>command and control servers</strong></a>. From these servers it receives instructions, keys are exchanged or new functions are loaded in the form of payloads. If you want to analyze unknown Malware, it is a good first step to find out if the malware connects to a server.</p>
<p>In this blog article i will show you, how to quickly and easily create a small network analysis tool for TCP connections with Tycho. The goal is to detect when a process connects to a server, find out the address of the server, and report what data is exchanged.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Automatically Detect Winnti Malware Using Tycho and YARA Rules]]></title>
            <link>https://www.cyberus-technology.de/posts/2020-07-13-winnti-detector.html</link>
            <guid>https://www.cyberus-technology.de/posts/2020-07-13-winnti-detector.html</guid>
            <pubDate>Sun, 12 Jul 2020 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>This blog gives a brief description of <a href="https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/"><strong>Winnti</strong></a>, a malware well known for attacking german DAX companies, an introduction on how it works, other methods of how to detect Winnti and my own solution using <a href="https://www.cyberus-technology.de/products/tycho.html"><strong>Tycho</strong></a> and <a href="https://virustotal.github.io/yara/"><strong>YARA</strong></a>. The script can detect Winnti injected code in a process by exploiting the malware’s behavior. The Winnti detector script is the fundament of the Winnti detective script, which will be used to extract the configuration data of the Winnti malware sample. The configuration data holds valuable information about the company that has been targeted by the sample discovered by the Winnti detector.</p>
<p>Winnti is injecting its code into an instance of <code>svchost.exe</code>. This means by dumping the virtual memory of each process and checking it with the specific <strong>YARA rule</strong> one can detect if Winnti is active on the target PC. Fortunately, dumping virtual memory of a process is really easy and convenient with <strong>Tycho</strong> and the following will show you how it’s done.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Creating memory dumps for Volatility using Tycho]]></title>
            <link>https://www.cyberus-technology.de/posts/2020-04-03-memdump.html</link>
            <guid>https://www.cyberus-technology.de/posts/2020-04-03-memdump.html</guid>
            <pubDate>Thu, 02 Apr 2020 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>In this article I present a python script that combines <a href="https://www.cyberus-technology.de/products/tycho.html"><strong>Tycho</strong></a> and <a href="https://github.com/volatilityfoundation/volatility"><strong>Volatility</strong></a> in order to analyze physical memory from a target machine. This is especially important when dealing with unknown malware samples. Unlike other approaches, <strong>Tycho</strong> allows an analyst to carefully monitor processes without ever having to fear that the malware could detect the analyst - read more about this <a href="https://blog.cyberus-technology.de/posts/2018-05-17-tycho-launch.html">here</a>. For example if a machine is suspected to be infected by some unknown malware, Tycho can be used to extract the possibly malicious program for further analysis using <strong>Volatility</strong> and a special <strong>Tycho Python script</strong>, that I developed during my internship and present in this article. The script is able to reliably create memory dumps of a target PC which have the right format to be analyzed by Volatility.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Defeating the Packing of Malware Using Execute After Write]]></title>
            <link>https://www.cyberus-technology.de/posts/2020-02-12-execute-after-write.html</link>
            <guid>https://www.cyberus-technology.de/posts/2020-02-12-execute-after-write.html</guid>
            <pubDate>Tue, 11 Feb 2020 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>In this article, I will show how easy and fast it is to dump the payload of a packed malware using a simple <a href="https://cyberus-technology.de/posts/2018-01-02-fun-with-python-and-tycho.html">pyTycho</a> python script. This explanation is based on the semantic breakpoints feature of <a href="https://cyberus-technology.de/products/tycho2.html">Tycho</a> and its open-source library <code>pyTycho</code>. If you are not familiar with Tycho, you can have a look at the previous <a href="https://www.cyberus-technology.de/blog.html">blogs</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Tycho-based Dashboard to Detect Gandcrab]]></title>
            <link>https://www.cyberus-technology.de/posts/2020-02-04-dashboard.html</link>
            <guid>https://www.cyberus-technology.de/posts/2020-02-04-dashboard.html</guid>
            <pubDate>Mon, 03 Feb 2020 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>This article demonstrates how Tycho can be used to gain valuable data on how a process or malware sample behaves to therefore detect said sample successfully. With the help of the ELK (Elasticsearch, Logstash, Kibana) stack it is possible to display the gained data in a dashboard to visualize how the sample behaves.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[TSX Asynchronous Abort]]></title>
            <link>https://www.cyberus-technology.de/posts/2019-11-12-taa.html</link>
            <guid>https://www.cyberus-technology.de/posts/2019-11-12-taa.html</guid>
            <pubDate>Mon, 11 Nov 2019 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>Today a new variant of the <a href="https://zombieloadattack.com">ZombieLoad</a> family of side-channel attacks has been made public. This new variant is called TSX Asynchronous Abort (TAA). TAA works on all recent Intel processors that support Intel TSX, including Intel’s most recent Cascade Lake processors.</p>
<p>In light of yet another side-channel attack, Cyberus Technology announces the start of a <a href="https://opensource.sotest.io/">public side-channel mitigation test and benchmarking lab</a>. This new lab will enable us to evaluate new side-channel attacks and new mitigations against such attacks in a quick and automated manner. Please refer to the <a href="/posts/2019-11-12-side-channel-lab.html">release announcement</a> for in-depth information.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Cyberus Technology Announces Side-Channel Lab]]></title>
            <link>https://www.cyberus-technology.de/posts/2019-11-12-side-channel-lab.html</link>
            <guid>https://www.cyberus-technology.de/posts/2019-11-12-side-channel-lab.html</guid>
            <pubDate>Mon, 11 Nov 2019 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>In light of <a href="/posts/2019-11-12-taa.html">yet another side-channel attack</a>, Cyberus Technology announces the a <a href="https://opensource.sotest.io">public side-channel mitigation test and benchmarking lab</a>. This new lab will enable us to evaluate new side-channel attacks and new mitigations against such attacks in a quick and automated manner.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[File tracking with Tycho]]></title>
            <link>https://www.cyberus-technology.de/posts/2019-08-20-file-tracking-with-tycho.html</link>
            <guid>https://www.cyberus-technology.de/posts/2019-08-20-file-tracking-with-tycho.html</guid>
            <pubDate>Mon, 19 Aug 2019 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>Before diving deep into the analysis of unknown malware, some basic knowledge about its behavior is required. As a starting point, it is useful to observe the files the malware touches and changes. Tycho can help to automate the observation of file creation and modification, giving the malware analyst a good overview of its behavior. In this blog entry, I will show you how to build a file tracker with Tycho.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Reverse Engineering with Tycho]]></title>
            <link>https://www.cyberus-technology.de/posts/2019-06-04-software-analysis-with-tycho.html</link>
            <guid>https://www.cyberus-technology.de/posts/2019-06-04-software-analysis-with-tycho.html</guid>
            <pubDate>Mon, 03 Jun 2019 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>Reverse engineering a software is not an easy task. Especially not if you do this for the first time.</p>
<p>Hi, my name is Sebastian Manns. I study “general and digital forensics”. Since one month I am a trainee at Cyberus Technology and my job is Software/Malware Analysis with <a href="https://www.cyberus-technology.de/products/tycho.html">Tycho</a>.</p>
<p>In my first blog entry I will show you how easy it is to evaluate and manipulate system calls with Tycho using <a href="https://github.com/a0rtega/pafish">Pafish</a> as an example.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Bygone, forgotten, over? One year after Meltdown of processor security]]></title>
            <link>https://www.cyberus-technology.de/posts/2019-05-29-1yr-meltdown.html</link>
            <guid>https://www.cyberus-technology.de/posts/2019-05-29-1yr-meltdown.html</guid>
            <pubDate>Tue, 28 May 2019 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>Do you recall the year change 2017/18? Of course, I am not referring to the New Year’s resolutions usually getting out of sight after a couple of weeks. Back then, I (together with a small team of other security researchers) was waiting for <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00088.html">Intel to disclose security vulnerabilities</a> we had discovered in its microprocessor hardware. We expected a fair bit of excitement because the industry had been scrambling to get mitigations in place. However I was thoroughly gobsmacked by the kind of delayed fireworks unfolding in the media. More than a year has elapsed since then so it is only fair to ask what is left beyond the sound and smoke - and why it was not the beginning of the end of the familiar IT universe, as predicted by a couple of <a href="https://www.zdnet.com/article/why-intel-x86-must-die-our-cloud-centric-future-depends-on-open-source-chips-meltdown/">pessimists</a>.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[ZombieLoad: Cross Privilege-Boundary Data Leakage]]></title>
            <link>https://www.cyberus-technology.de/posts/2019-05-14-zombieload.html</link>
            <guid>https://www.cyberus-technology.de/posts/2019-05-14-zombieload.html</guid>
            <pubDate>Mon, 13 May 2019 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>ZombieLoad is a novel category of side-channel attacks which we refer to as <strong>data-sampling attack</strong>. It demonstrates that faulting load instructions can transiently expose private values of one Hyperthread sibling to the other. This new exploit is the result of a collaboration between Michael Schwarz, Daniel Gruss and Moritz Lipp from Graz University of Technology, Thomas Prescher and Julian Stecklina from Cyberus Technology, Jo Van Bulck from KU Leuven, and Daniel Moghimi from Worcester Polytechnic Institute.</p>
<p>In this article, we summarize the implications and shed light on the different attack scenarios across CPU privilege rings, OS processes, virtual machines, and SGX enclaves, and give advice over possible ways to mitigate such attacks.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Tycho 1.2 released with Process Listing, Cuckoo Sandbox Integration and Autostart Breakpoints]]></title>
            <link>https://www.cyberus-technology.de/posts/2019-01-07-tycho-1-2.html</link>
            <guid>https://www.cyberus-technology.de/posts/2019-01-07-tycho-1-2.html</guid>
            <pubDate>Sun, 06 Jan 2019 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>We are proud to announce that today we are releasing Tycho 1.2. This release features Process Listing, Cuckoo Sandbox Integration and the Autostart Semantic Breakpoint.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de/./images/tycho.png">
            </enclosure>
        </item>
        <item>
            <title><![CDATA[Tycho 1.1 released with USB3 Debug Port Support and Syscall Interpretation]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-10-02-tycho-1-1.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-10-02-tycho-1-1.html</guid>
            <pubDate>Mon, 01 Oct 2018 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>We are proud to announce that today we are releasing Tycho 1.1. This release features USB 3 Debug Port Support, System Call Interpretation, and a plugin for IDA Pro that shows memory information directly within IDA.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de/./images/tycho.png">
            </enclosure>
        </item>
        <item>
            <title><![CDATA[L1 Terminal Fault Vulnerability]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-08-14-l1-terminal-fault.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-08-14-l1-terminal-fault.html</guid>
            <pubDate>Mon, 13 Aug 2018 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>After <a href="https://meltdownattack.com/">Meltdown</a> (see also <a href="http://blog.cyberus-technology.de/posts/2018-01-03-meltdown.html">our article about Meltdown</a>) and <a href="https://spectreattack.com/">Spectre</a>, more vulnerabilities in out-of-order CPUs have been uncovered that use similar side channels. This article is about the <a href="https://software.intel.com/security-software-guidance/software-guidance/l1-terminal-fault"><strong>L1 Terminal Fault</strong> vulnerability</a>, a meltdown-style attack that is also effective against up-to-date system software incorporating KPTI-like patches. <em>L1 Terminal Fault</em> actually refers to three different vulnerabilities with the ancestor being the <a href="https://foreshadowattack.eu/"><strong>Foreshadow</strong> vulnerability</a> that was published at this year’s USENIX Security Symposium. While the article authors focus on SGX security aspects we are more concerned about implications for virtualization as it also enables <strong>crossing virtual machine borders</strong> with uncomfortable ease.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Intel LazyFP vulnerability: Exploiting lazy FPU state switching]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-06-06-intel-lazyfp-vulnerability.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-06-06-intel-lazyfp-vulnerability.html</guid>
            <pubDate>Tue, 05 Jun 2018 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>After <a href="https://meltdownattack.com/">Meltdown</a> (see also <a href="https://blog.cyberus-technology.de/posts/2018-01-03-meltdown.html">our article about Meltdown</a>) and <a href="https://spectreattack.com/">Spectre</a>, which were publicly disclosed in January, the Spectre V3a and V4 vulnerabilities followed in May (see also <a href="https://blog.cyberus-technology.de/posts/2018-05-22-intel-store-load-spectre-vulnerability.html">our article about Spectre V4</a>). <a href="https://www.heise.de/security/meldung/Spectre-NG-Intel-Prozessoren-von-neuen-hochriskanten-Sicherheitsluecken-betroffen-4039302.html">According to the German IT news publisher Heise</a>, the latter might be part of 8 new vulnerabilities in total that are going to be disclosed in the course of the year.</p>
<p>Earlier this year, Julian Stecklina (Amazon) and Thomas Prescher (Cyberus Technology) jointly discovered and responsibly disclosed another vulnerability that might be part of these, and we call it <strong>LazyFP</strong>. LazyFP (CVE-2018-3665) is an attack targeting operating systems that use lazy FPU switching. This article describes what this attack means, outlines how it can be mitigated and how it actually works.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Spectre V4: Store-Load Vulnerability]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-05-22-intel-store-load-spectre-vulnerability.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-05-22-intel-store-load-spectre-vulnerability.html</guid>
            <pubDate>Mon, 21 May 2018 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>After <a href="https://meltdownattack.com/">Meltdown</a> (see also <a href="https://blog.cyberus-technology.de/posts/2018-01-03-meltdown.html">our article about Meltdown</a>) and <a href="https://spectreattack.com/">Spectre</a>, more vulnerabilities in out-of-order CPUs have been uncovered that use similar attack vectors.</p>
<p>This article is about the new variant 4 of the Spectre attack that works without misleading the branch predictor. Instead, it exploits an implementation detail of Intel’s <a href="https://en.wikipedia.org/wiki/Memory_disambiguation"><em>memory disambiguation</em></a> technique inside the CPU’s pipeline.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Introducing: Tycho Malware Forensics Suite]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-05-17-tycho-launch.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-05-17-tycho-launch.html</guid>
            <pubDate>Wed, 16 May 2018 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>The Cyberus <strong>Tycho</strong> Malware Forensics Tool is now available for purchase.</p>
<p><strong>Tycho</strong> is a uniquely powerful malware forensics tool suite which aids and expedites the work of manual malware analyst and software reverse engineers – <strong>a malware debugger on steroids</strong>.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de//assets/images/tycho.png">
            </enclosure>
        </item>
        <item>
            <title><![CDATA[Windows on iSCSI - Part 3/3]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-03-26-windows-on-iscsi-part3.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-03-26-windows-on-iscsi-part3.html</guid>
            <pubDate>Sun, 25 Mar 2018 22:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>As an important step towards automating the creation of Windows disk assets/images, we will take a closer look at the Critical Device Database (CDDB) inside the Windows registry. The goal is to transform any locally installed instance to be bootable from iSCSI without having to run a full installation onto an iSCSI disk before.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de//assets/images/iscsi_lspci.png">
            </enclosure>
        </item>
        <item>
            <title><![CDATA[Windows on iSCSI - Part 2/3]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-03-12-windows-on-iscsi-part2.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-03-12-windows-on-iscsi-part2.html</guid>
            <pubDate>Sun, 11 Mar 2018 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>In this article, we will describe how an ordinary Windows 7 installation can be converted to be booted from iSCSI. We will cover the particularities of the Windows network boot process and and elaborate on the differences to the normal boot. We then describe our solution using some registry modifications.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de//assets/images/iscsi_cddb_nic.png">
            </enclosure>
        </item>
        <item>
            <title><![CDATA[Windows on iSCSI - Part 1/3]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-02-26-windows-on-iscsi-part1.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-02-26-windows-on-iscsi-part1.html</guid>
            <pubDate>Sun, 25 Feb 2018 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>This series of three posts is about installing Windows 7 on an iSCSI disk. In this first article, we install it using qemu and iPXE and cover some of the pitfalls and particularities of this install method, as well as the topic of duplicating the resulting disk for use in machines of the same type. Two more follow-up posts will cover details of the network boot process, leading to a method of converting an existing installation to be iSCSI-bootable.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de//assets/images/iscsi_setup.png">
            </enclosure>
        </item>
        <item>
            <title><![CDATA[Tracking file system access of individual processes]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-02-05-list-created-files.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-02-05-list-created-files.html</guid>
            <pubDate>Sun, 04 Feb 2018 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>In the last article, we have shown how to interrupt a process running in an unpatched Windows system on top of the Cyberus virtualization platform before it executes specific system calls using the Tycho Python API. This time, we demonstrate how to implement a short but useful script that logs which files are accessed by a process of our choice.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Windows system call parameter analysis]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-01-22-system-call-parameter-analysis.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-01-22-system-call-parameter-analysis.html</guid>
            <pubDate>Sun, 21 Jan 2018 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>Due to its introspection capabilities, the Cyberus virtualization platform is able to analyze Windows system calls. In this article we demonstrate how simple it is to extract system call parameters out of a running windows machine with Python using the Tycho API.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de//assets/images/pafish_start.jpg">
            </enclosure>
        </item>
        <item>
            <title><![CDATA[Simple DLL injection detection]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-01-04-simple-dll-injection-detection.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-01-04-simple-dll-injection-detection.html</guid>
            <pubDate>Wed, 03 Jan 2018 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>In this article we are going to play with a DLL injection tool on a Windows system that is running on top the Cyberus Virtualization Platform. Using the Tycho Python API, we will see how dead simple it is to check if a process has been subject to DLL injection.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de//assets/images/tycho_calc_remotedll_injected_suspender.png">
            </enclosure>
        </item>
        <item>
            <title><![CDATA[Meltdown]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-01-03-meltdown.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-01-03-meltdown.html</guid>
            <pubDate>Tue, 02 Jan 2018 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p><strong>Meltdown</strong> is an attack on the general memory data security of computers with the Intel x86 architecture. Two members of the founder team of Cyberus Technology GmbH were <a href="https://meltdownattack.com/">among the first experts to discover this vulnerability</a>. This article describes how Meltdown actually works and also examines the mitigations that have been patched into the most widespread operating systems while the information embargo was still intact.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de//assets/images/meltdown-front.svg">
            </enclosure>
        </item>
        <item>
            <title><![CDATA[Fun with Python and Tycho]]></title>
            <link>https://www.cyberus-technology.de/posts/2018-01-02-fun-with-python-and-tycho.html</link>
            <guid>https://www.cyberus-technology.de/posts/2018-01-02-fun-with-python-and-tycho.html</guid>
            <pubDate>Mon, 01 Jan 2018 23:00:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>This article demonstrates how simple it is to setup our analysis tool Tycho and plays with the Tycho Python API in order to outline its potential. We will pause and resume processes, read interesting process information, and inject errors using the Tycho Python API.</p>]]></content:encoded>
            <enclosure url="https://www.cyberus-technology.de//assets/images/tycho_hardware_setup_example.jpg">
            </enclosure>
        </item>
    </channel>
</rss>