Evading Sysmon Dns Monitoring In 2026
Back in 2019, XPN published Evading Sysmon DNS Monitoring, documenting an interesting look into how Sysmon collected DNS telemetry through ETW. The research was performed against Sysmon 10.1 and de...
Back in 2019, XPN published Evading Sysmon DNS Monitoring, documenting an interesting look into how Sysmon collected DNS telemetry through ETW. The research was performed against Sysmon 10.1 and de...
The Growing Importance of Windows Credential Theft Tags: Memory Forensics · Volatility 3 · WinPmem · ntlm hash Overview We acquire a full physical memory image from a live Windows 11 system ...
Browser Dumping: The Core Tactic Behind Most Infostealers This blog contains my own research collected from the internet, along with ideas from other blogs and studies. While many parts are wri...
Analyzing Avast AV: Kernel Hooking and Driver Reverse Engineering Summary We walk through undocumented internals such as CKCL, PerfInfoLogSysCallEntry, HalPrivateDispatch / HalpPerformanceCounter,...
Chain Leading To Silent Elevation Summary A chained technique has been identified that allows a local, unprivileged attacker to achieve silent privilege escalation to administrator by bypass...
Introduction to AutoIt Malware Analysis In the world of malware analysis, encountering different scripting languages used for malicious purposes is an essential part of expanding our understandi...