frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: ShadowStrike EDR/XDR Kernel Sensor Development

1•Soocile•1h ago
I've been building an open-source kernel-mode EDR/XDR sensor called Phantom Sensor for about two years now as a solo project. It just hit a milestone I'm pretty excited about - the driver loads cleanly on Windows 11, passes Driver Verifier with all standard flags enabled, and survives normal use without crashing.

The kernel sensor (PhantomSensor) is a WFP+minifilter driver sitting at altitude 385210. It's written in C targeting the WDK, roughly 370k lines across 70+ modules. Some of what it does:

ObRegisterCallbacks for process/thread handle stripping (anti-injection, anti-debug) Minifilter callbacks with stream contexts for file monitoring, ransomware backup engine, section object tracking WFP callouts for network inspection - TCP stream reassembly, DNS monitoring, C2 beacon detection, TLS fingerprinting PsSetCreateProcessNotifyRoutineEx / PsSetLoadImageNotifyRoutine for behavioral analysis ETW provider + consumer for kernel telemetry Registry callback for persistence detection (Run keys, services, scheduled tasks) Process hollowing detection via VAD analysis + PE header comparison Syscall table monitoring, direct syscall detection, Heaven's Gate detection , Halo's Gate detections + Hell's Gate detections Lookaside lists for hot-path allocations, rundown protection for safe teardown, reference-counted object lifetimes The behavioral engine tracks attack chains and maps to MITRE ATT&CK techniques. Thread protection module does per-process activity tracking with hash-bucketed trackers and rate limiting - had a fun use-after-free in there (refcount off-by-one on newly inserted trackers, InsertTailList caught the corrupted list entry - classic).

It's been a long road of analyzing dump reports using kd.exe(kernel debugger) windbg x64 and finding the errors that triggered the BSOD.Here are some: WORKER_INVALID from double-queuing IO_WORKITEM on periodic timers. Stack overflows from 4KB structs in image load callbacks. IRQL_NOT_LESS_OR_EQUAL from ERESOURCE without KeEnterCriticalRegion. Each one taught me something.

The codebase is AGPL v3. But understand it is still not completed(There is not only kernel-sensor) we have a Beta 2028 target for the full product especially 3 products(Phantom XDR Phantom EDR and Phantom Consumer solutions below the ShadowStrike brand.

If you want to support or follow the journey of developing a Kernel-driver and a user-mode agent for the ShadowStrike Phantom products:

I ran a 5-day experiment to see how fast Google reshapes your ad profile

https://nanobuilds.substack.com/p/how-fast-can-you-reshape-what-google
1•nanobuilds•1m ago•0 comments

Show HN: Discard – a daily card-clearing puzzle that tightens rules each round

https://www.playdiscard.com/
1•tzual•1m ago•0 comments

AI chatbots agree on what to say about candidates, but not where they got it

https://caucusai.substack.com/p/same-answers-different-sources
1•m-hodges•1m ago•0 comments

Show HN: Dank-py – turn existing Python agents into microservices in 2 commands

https://github.com/Delta-Darkly/dank-py
1•deltadarkly•1m ago•0 comments

"It feels like Squid Game": China's workers scramble to keep up in the AI race

https://restofworld.org/2026/china-ai-anxiety-openclaw-jobs-redundancy/
1•Brajeshwar•1m ago•0 comments

Transformers as Constrained Optimization

https://jiha-kim.github.io/posts/transformers-as-constrained-optimization/
1•ibobev•4m ago•0 comments

InSpatio-World – Turn any video into a dynamic 4D world

https://inspatio.github.io/inspatio-world/
1•EliasWatson•6m ago•0 comments

A.I. Agents: They're Fun. They're Useful. But Don't Give Them the Credit Card

https://www.nytimes.com/2026/03/19/technology/ai-agents-uses.html
2•buzznewswebsite•6m ago•0 comments

Mockline – Spin up live mock API from OpenAPI specs in seconds

1•trillionclues•7m ago•0 comments

World Models: Computing the Uncomputable

https://www.notboring.co/p/world-models
2•lairv•8m ago•0 comments

Show HN: RustFS – Migrate from MinIO via simple binary replacement

https://rustfs.dev/binary-replacement-a-simple-way-to-migrate-from-minio-to-rustfs/
1•elvinagy•10m ago•0 comments

What if Ai is embedding subliminal messages in the Ai slop videos?

1•AvacadoJuice•10m ago•0 comments

No-build, no-NPM, SSR-first JavaScript framework if you hate React, love HTML

https://qitejs.qount25.dev
2•usrbinenv•12m ago•0 comments

Gramsci's Nightmare: AI, Platform Power and the Automation of Cultural Hegemony

https://ethanzuckerman.com/2025/12/05/gramscis-nightmare-ai-platform-power-and-the-automation-of-...
1•Pamar•12m ago•0 comments

One million tokens won't save your engineering standards

https://straion.com/blog/1m-tokens-wont-save-your-engineering-standards/
1•bugsense•13m ago•0 comments

Show HN: Budibase Agents Beta – model-agnostic AI agents for internal workflows

https://budibase.com/blog/updates/ai-agents-beta/
4•mjashanks•13m ago•0 comments

An oral history of Bank Python (2021)

https://calpaterson.com/bank-python.html
1•calpaterson•13m ago•0 comments

Virtue and tasks that I don't have time to do

http://alexanderpruss.blogspot.com/2026/03/virtue-and-tasks-that-i-dont-have-to-do.html
1•bookofjoe•13m ago•0 comments

Efficient Lossless Compression of Scientific Floating-Point Data on CPUs and GPU

https://dl.acm.org/doi/10.1145/3669940.3707280
1•blakepelton•14m ago•1 comments

Connecting the Dots in a JFR Recording

https://jbachorik.github.io/posts/decorateby-cross-signal-jfr
1•tanelpoder•16m ago•0 comments

You Might Debate It – If You Could See It

https://blog.jim-nielsen.com/2026/opacity-of-generative-tools/
1•speckx•18m ago•0 comments

When Did That Hotspot Happen?

https://jbachorik.github.io/posts/stackprofile-jfr
1•tanelpoder•18m ago•0 comments

Foundation Labs

https://www.foundation-labs.xyz/
1•cosiiine•18m ago•0 comments

OpenBSD: PF queues break the 4 Gbps barrier

https://undeadly.org/cgi?action=article;sid=20260319125859
14•defrost•18m ago•2 comments

A brief history of AI coding, from Copilot to next-gen agents

https://www.coderabbit.ai/blog/a-very-brief-history-of-ai-coding-from-copilot-to-next-gen-agents
2•dmkravets•18m ago•0 comments

Grumpy Website

https://grumpy.website/
3•FergusArgyll•18m ago•0 comments

Email Providers of Dutch Municipalities

https://mxmap.nl/
2•8organicbits•19m ago•0 comments

I turned Markdown into a protocol for generative UI

https://fabian-kuebler.com/posts/markdown-agentic-ui/
4•FabianCarbonara•19m ago•1 comments

Show HN: AgentDeals – Developer pricing discovery for AI agents

https://github.com/robhunter/agentdeals
1•rhunter•19m ago•0 comments

Thoughts on "The Machine Stops"

https://rznicolet.com/2026/03/19/thoughts-on-the-machine-stops/
1•rznicolet•19m ago•1 comments