Technical Writeups
Windows internals research for defensive understanding.
SeImpersonatePrivilege to SYSTEM
Token impersonation from service accounts. Named pipes, SYSTEM connections, session isolation.
Persistence by Privilege Level
What attackers can do at user, admin, and SYSTEM levels. Where to hunt at each tier.
LNK Files Are Dead
Why shortcuts no longer work for initial access. ISO, HTA, and MSI alternatives.
regsvr32 as Execution Vector
COM registration abuse. Squiblydoo, OCX droppers, and detection strategies.
Scheduled Task Stealth
Process tree manipulation, naming conventions, interval randomization, COM-based creation.
Why Understanding Beats Obfuscation
The difference between using tools and knowing why they work. PEB walking implementation.
Process Hollowing (RunPE)
Replace a legitimate process's code with your payload. PE parsing, NtUnmapViewOfSection, section mapping.
Classic DLL Injection
CreateRemoteThread + LoadLibrary. Why it's detected, what it teaches, and better alternatives including APC injection.
UAC Bypass via fodhelper
Registry hijack of HKCU ms-settings protocol handler. Medium to High integrity without a UAC prompt.
Token Stealing: Admin to SYSTEM
OpenProcess on winlogon, DuplicateTokenEx, CreateProcessWithTokenW. The Admin → SYSTEM chain in full.
AV Evasion Fundamentals
Behavioral AV vs AMSI — why they're different problems. Sandbox detection, FUD loader design, PEB walking, XOR string encryption, memory-only execution.
Scanner Detection & Honeypot Redirection
Detecting Shodan, Censys, Infrawatch by IP range + payload signature. iptables PREROUTING redirect, auto-detection of unknown scanners, WHOIS-enriched alerts.
Single-Port C2 Design
The migration protocol problem that breaks SYSTEM shells. Single-port fix, <<END>> sync, AES-256-CBC channel encryption, anti-sandbox timer.
Chrome Credential Harvesting
SQLite Login Data + DPAPI + AES-256-GCM. How Chrome encrypts saved passwords and how stealers extract them.