Post #62
1.27K
1734722992877.pdf1 MB
Exploring Kernel Callbacks in Windows for Red Teamers / Developers
SE Showing posts older than #63 · Back to latest
A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Callback Routine registering and ZwTerminateProcess
Call stacks are an understated yet often important source of telemetry for EDR products. They can provide vital context to an event and be an extremely powerful tool in determining false positives from true positives (especially for credential theft events such as handle access to lsass).
Obfusk8 is a lightweight, header-only C++17 library designed to significantly enhance the obfuscation of your applications, making reverse engineering a substantially more challenging endeavor. It achieves this through a diverse set of compile-time and runtime techniques aimed at protecting your code's logic and data.
AIYA MMD - means Attack and Introduction or (Android and IOS), start Your Adventure in Mobile Malware Development. also AIYA means AIYA Nurkhankyzy.
Forwarded from Order of Six Angles
YouTube Malware Loader Reverse Engineering with IDA Pro (Stream - 06/05/2025) In this stream we reverse engineered a malware loader with IDA Pro, including its anti-analysis, persistence, COM UAC Bypass, command-line spoofing, C2, process injection, and TCP proxy functionality. Learn how to reverse engineer malware: https://train…Methodology
From a C project through assembly to shellcode Hasherezade