Post #1259 115 Apr 21, 2023, 21:13 UTC Hiding in Plain Sight: Unlinking Malicious DLLs from the PEB https://blog.christophetd.fr/dll-unlinking/ Christophe Tafani-Dereeper Hiding in Plain Sight: Unlinking Malicious DLLs from the PEB - Christophe Tafani-Dereeper In this post, we take a look at an anti-forensics technique that malware can leverage to hide injected DLLs. We dive into specific details of the Windows Process Environment Block (PEB) and how to abuse it to hide a malicious loaded DLL. Background: You may…