Official account for Grapl - the open source graph based #DetectionAndResponse platform. github.com/grapl-security…

San Francisco, CA
Grapl Inc. retweeted
🦀📕 All chapters of my book, Rust Atomics and Locks, are now freely available online: marabos.nl/atomics/ Enjoy! ✨
61
624
2,891
306,453
Grapl Inc. retweeted
Great write-up by @chompie1337 into trying to exploit Firecracker and luckily it withstood the attempt. It's really impressive how much @GraplSec audits the security of the components they rely on, and appreciated they post even investigations like this that didn't find 0-day.
Firecracker is a microVM manager in #Rust that powers #AWS services like Lambda and Fargate. It's also one of the key components of Grapl's multi-tenant isolation. A critical dependency deserves some red teaming - here's how we attacked AWS' Firecracker. graplsecurity.com/post/attac…
1
7
42
Firecracker is a microVM manager in #Rust that powers #AWS services like Lambda and Fargate. It's also one of the key components of Grapl's multi-tenant isolation. A critical dependency deserves some red teaming - here's how we attacked AWS' Firecracker. graplsecurity.com/post/attac…
10
48
Using code to describe your infrastructure unlocks a lot of expressive power, which is why we use @PulumiCorp to automate our deployments. When we couldn't find providers for some of the services we use, we ended up making some. Learn how: graplsecurity.com/post/pulum…
8
23
Grapl Inc. retweeted
You can now manage Buildkite-as-code using @PulumiCorp 🔥 🙌 and 💚 to @GraplSec for sharing it with the world. You can get started with it here: pulumi.com/registry/packages…
ICYMI: at #PulumiUP we announced that we now have over 100 integrations including new additions from @OracleCloud, @databricks, @eventstore, @checklyHQ, @buildkite, @jfrog Artifactory, @elastic Cloud, @TwingateHQ, @Scaleway, @Tailscale and @SlackHQ: pulumi.com/pulumi-up/?utm_so…
4
18
Put an io_uring on it: Exploiting the Linux Kernel via @GraplSec buff.ly/3CY89wT #linux
3
7
Grapl Inc. retweeted
Thrilled to share my new blog post: Put an io_uring on it: Exploiting the Linux kernel. Follow me while I learn a new kernel subsystem + its attack surface, find an 0day, build an exploit, + come up with some new tricks. I go deep and demystify the process graplsecurity.com/post/iou-r…
41
591
2,217
#io_uring is a new #Linux syscall interface, designed for performance. It redefines how apps interact with the kernel, even inside a #sandbox. In our blog, we cover the attack surface, find a vuln, and use advanced kernel exploit techniques to gain #root graplsecurity.com/post/iou-r…
16
71
Grapl Inc. retweeted
This is an outstanding work. I've had the privilege to see @wipawel work thru this research. The post has many references, excellent background info and offers a methodology that can be used for other experiments too (besides the cool finding!)
Today we present deep research from our @wipawel into the branch predictor of AMD CPUs and abusing its behavior to exploit Spectre v1 much more easily than previously understood, culminating in reproducing an arbitrary kernel mem leak PoC in only 3 days. grsecurity.net/amd_branch_mi…
9
26
Grapl Inc. retweeted
computers were a mistake
2
1
10
Grapl Inc. retweeted
Could not be more excited to get this book from @snyksec's #31DaysOfSecurity giveaway today! I'm blown away by how thoughtful this choice is! Can't wait to integrate what I learn into my work @GraplSec! So grateful!! What an excellent start to my week!
1
6
19
Grapl Inc. retweeted
So excited to finally release my blog post- Kernel Pwning with eBPF: a Love Story. I cover eBPF, the verifier, debugging, exploitation, mitigations and other cool findings! I do root cause analysis and exploit CVE-2021-3490 for LPE with PoC included. graplsecurity.com/post/kerne…
28
528
1,720
#eBPF is a powerful #Linux capability for devs who want to run code in the kernel, but it also makes for great attack surface. In our blog, @chompie1337 digs into eBPF, explains how it works, and demonstrates a local privilege escalation exploit! graplsecurity.com/post/kerne…
23
83
We have! Very happy to have @d0nutptr onboard!
Has anyone else noticed the massive amount @d0nutptr gives the community? Quietly. And consistently. Respect.
8
One year ago #SigRed (CVE-2020-1350) was patched. The RCE vulnerability allows an attacker to gain access as Domain Admin and own the entire network. Read our writeup on the the first public exploit from our very own @chompie1337! graplsecurity.com/post/anato…
99
223
Grapl Inc. retweeted
writing secure C right now by just focusing really hard. should tell other ppl about this
8
19
144