⤷ Title: EDR Atlatma Teknikleri: User-Mode’da PEB Manipülasyonu
════════════════════════
𐀪 Author: Pınar Taşgın
════════════════════════
ⴵ Time: Sat, 14 Jun 2025 18:10:27 GMT
════════════════════════
⌗ Tags: #peb #cybersecurity #windows_api_hooking #windows
════════════════════════
𐀪 Author: Pınar Taşgın
════════════════════════
ⴵ Time: Sat, 14 Jun 2025 18:10:27 GMT
════════════════════════
⌗ Tags: #peb #cybersecurity #windows_api_hooking #windows
Medium
EDR Atlatma Teknikleri: User-Mode’da PEB Manipülasyonu
PEB Nedir?
⤷ Title: Shanya Crypter Is the New Ransomware Toolkit: Uses Kernel Driver Abuse to Kill EDR
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:40:01 +0000
════════════════════════
⌗ Tags: #Malware #DLL Doppelganger #EDR Killer #Kernel Abuse #PEB Manipulation #ransomware #Shanya Crypter #Sophos #VX Crypt
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 09 Dec 2025 00:40:01 +0000
════════════════════════
⌗ Tags: #Malware #DLL Doppelganger #EDR Killer #Kernel Abuse #PEB Manipulation #ransomware #Shanya Crypter #Sophos #VX Crypt
Daily CyberSecurity
Shanya Crypter Is the New Ransomware Toolkit: Uses Kernel Driver Abuse to Kill EDR
The Shanya Crypter (VX Crypt) is a new PaaS used by Akira/Medusa to bypass EDR. It deploys a kernel driver attack to kill security products and uses PEB manipulation for stealth.
⤷ Title: The Ghost in the Kernel: Inside KittyLoader’s Elite Anti-Analysis Arsenal
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 04:30:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool #anti_forensics #Assembly #C_Runtime Hijacking #ChaCha20 #EDR evasion #KittyLoader #LdrCallEnclave #malware analysis #PEB Unlinking #Process injection
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 31 Dec 2025 04:30:33 +0000
════════════════════════
⌗ Tags: #Open Source Tool #anti_forensics #Assembly #C_Runtime Hijacking #ChaCha20 #EDR evasion #KittyLoader #LdrCallEnclave #malware analysis #PEB Unlinking #Process injection
Information Security News
The Ghost in the Kernel: Inside KittyLoader’s Elite Anti-Analysis Arsenal
KittyLoader is a highly evasive loader written in C / Assembly. Features Hijacks early execution by replacing the C runtime entrypoint (__scrt_common_main_seh) with custom assembly. Hides all modu…