πNew WriteupβοΈ
βββββββββββββββ
πDate: Mon, 02 Oct 2023 09:28:00 GMT
βββββββββββββββ
βοΈTitle: Intro to Syscalls & Windows internals for malware development Pt.1
βββββββββββββββ
πLink: https://medium.com/p/b5bb0cd90c52
βββββββββββββββ
Tags: #cybersecurity #penetration_testing #windows_internals #malware #red_team
βββββββββββββββ
πDate: Mon, 02 Oct 2023 09:28:00 GMT
βββββββββββββββ
βοΈTitle: Intro to Syscalls & Windows internals for malware development Pt.1
βββββββββββββββ
πLink: https://medium.com/p/b5bb0cd90c52
βββββββββββββββ
Tags: #cybersecurity #penetration_testing #windows_internals #malware #red_team
Medium
Intro to Syscalls & Windows internals for malware development Pt.1
Hello Everyone, over the years Iβve written many articles/summaries that for some reason I kept to myself and didnβt think to share themβ¦
πNew WriteupβοΈ
βββββββββββββββ
πDate: Wed, 25 Dec 2024 10:14:32 GMT
βββββββββββββββ
βοΈTitle: CreaciΓ³n de proceso en Windows
βββββββββββββββ
πLink: https://medium.com/p/d3c412cb07fd
βββββββββββββββ
Tags: #windows_internals #windows #research #malware #hacking
βββββββββββββββ
πDate: Wed, 25 Dec 2024 10:14:32 GMT
βββββββββββββββ
βοΈTitle: CreaciΓ³n de proceso en Windows
βββββββββββββββ
πLink: https://medium.com/p/d3c412cb07fd
βββββββββββββββ
Tags: #windows_internals #windows #research #malware #hacking
Medium
CreaciΓ³n de proceso en Windows
En este articulo hablaremos de los componentes clave que se involucran en la creaciΓ³n de procesos de la familia de funciones deβ¦
β€· Title: Ghostly Reflective PE Loaderβββhow to make a remote process inject a PE in itself
ββββββββββββββββββββββββ
πͺ Author: Sohail Saha
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 11 Mar 2025 18:26:53 GMT
ββββββββββββββββββββββββ
β Tags: #windows_internals #windows #malware #penetration_testing #red_team
ββββββββββββββββββββββββ
πͺ Author: Sohail Saha
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 11 Mar 2025 18:26:53 GMT
ββββββββββββββββββββββββ
β Tags: #windows_internals #windows #malware #penetration_testing #red_team
Medium
Ghostly Reflective PE Loaderβββhow to make a remote process inject a PE in itself
How to combine reflective DLL injection with Ghostly hollowing to make a remote process inject a PE in itself.
β€· Title: Understanding Windows Internals: An Introduction
ββββββββββββββββββββββββ
πͺ Author: Allow
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 02 Apr 2025 15:28:29 GMT
ββββββββββββββββββββββββ
β Tags: #windows_internals #cybersecurity #malware_development #malware #malware_analysis
ββββββββββββββββββββββββ
πͺ Author: Allow
ββββββββββββββββββββββββ
β΄΅ Time: Wed, 02 Apr 2025 15:28:29 GMT
ββββββββββββββββββββββββ
β Tags: #windows_internals #cybersecurity #malware_development #malware #malware_analysis
Medium
Understanding Windows Internals: An Introduction
Tags: #WindowsInternals #WindowsDevelopment #ReverseEngineering #OperatingSystems
β€· Title: What the Heck Is the Windows NT Kernel?
ββββββββββββββββββββββββ
πͺ Author: Raven Rover
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 01 Jun 2025 15:44:25 GMT
ββββββββββββββββββββββββ
β Tags: #windows_kernel #windows #linux_kernel #windows_internals #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Raven Rover
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 01 Jun 2025 15:44:25 GMT
ββββββββββββββββββββββββ
β Tags: #windows_kernel #windows #linux_kernel #windows_internals #cybersecurity
Medium
π§ What the Heck Is the Windows NT Kernel?
The Core of WindowsβββExplained for Cyber Curious Minds
β€· Title: Windows API-Part I: Because Buttons Donβt Click Themselves.
ββββββββββββββββββββββββ
πͺ Author: Sankadlikhit
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 30 Jun 2025 20:43:23 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #info #winapi #red_team #windows_internals
ββββββββββββββββββββββββ
πͺ Author: Sankadlikhit
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 30 Jun 2025 20:43:23 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #info #winapi #red_team #windows_internals
Medium
Windows API-Part I: Because Buttons Donβt Click Themselves.
In the world of Windows, Commander (Bill Gates) doesnβt let programs talk directly to the operating system. Instead, thereβs a messengerβ¦
β€· Title: My notes on βWindows Security InternalsβββA Deep Dive into Windows Authentication, Authorizationβ¦
ββββββββββββββββββββββββ
πͺ Author: Feghouli Hamza
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 27 Jul 2025 14:14:11 GMT
ββββββββββββββββββββββββ
β Tags: #windows #os_internals #security_research #windows_internals #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Feghouli Hamza
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 27 Jul 2025 14:14:11 GMT
ββββββββββββββββββββββββ
β Tags: #windows #os_internals #security_research #windows_internals #cybersecurity
Medium
My notes on βWindows Security InternalsβββA Deep Dive into Windows Authentication, Authorizationβ¦
The Windows Kernel Executive :
β€· Title: Evading ETW Techniques ( written in C):
ββββββββββββββββββββββββ
πͺ Author: Zanebilal
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 03 Oct 2025 18:41:39 GMT
ββββββββββββββββββββββββ
β Tags: #etw #evasion #windows_internals #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Zanebilal
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 03 Oct 2025 18:41:39 GMT
ββββββββββββββββββββββββ
β Tags: #etw #evasion #windows_internals #cybersecurity
Medium
Evading ETW Techniques ( written in C):
before we begin : the code discussed in this blog is evaluable in my GitHub repo : https://github.com/Zanebilal/ETW-Evasion
β€· Title: PE File Structure Explained : A Guide to for Reverse Engineers & Developers
ββββββββββββββββββββββββ
πͺ Author: Shaheer Yasir
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 05 Oct 2025 09:44:29 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #hacking #reverse_engineering #offensive_security #windows_internals
ββββββββββββββββββββββββ
πͺ Author: Shaheer Yasir
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 05 Oct 2025 09:44:29 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #hacking #reverse_engineering #offensive_security #windows_internals
Medium
PE File Structure Explained : A Guide to for Reverse Engineers & Developers
Hey there, Iβm Shaheer Yasir, aka Maverick. The Portable Executable (PE) format is the standard file format for executables, object codeβ¦
β€· Title: Blocking EDRs traffic: C-Based Tools That Block EDR Network Traffic via Windows Firewall and WFP
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 15 Dec 2025 08:07:20 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #EDR evasion #endpoint security #firewall rules #red team tools #WFP filters #Windows Defender Firewall #Windows Filtering Platform #Windows internals
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 15 Dec 2025 08:07:20 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #EDR evasion #endpoint security #firewall rules #red team tools #WFP filters #Windows Defender Firewall #Windows Filtering Platform #Windows internals
Penetration Testing Tools
Blocking EDRs traffic: C-Based Tools That Block EDR Network Traffic via Windows Firewall and WFP
New C-based tools demonstrate how EDR network traffic can be blocked using Windows Defender Firewall and WFP without disabling security software.
β€· Title: Windows Internals (COM objects)
ββββββββββββββββββββββββ
πͺ Author: Makarios Mamdouh
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 15 Mar 2026 09:53:28 GMT
ββββββββββββββββββββββββ
β Tags: #incident_response #windows_internals #cybersecurity #hacking #com_objects
ββββββββββββββββββββββββ
πͺ Author: Makarios Mamdouh
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 15 Mar 2026 09:53:28 GMT
ββββββββββββββββββββββββ
β Tags: #incident_response #windows_internals #cybersecurity #hacking #com_objects
Medium
Windows Internals
What is COM objects?
β€· Title: TryHackMe β Windows Fundamentals (Part II) Writeup
ββββββββββββββββββββββββ
πͺ Author: Manmath somure
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 20 Mar 2026 13:34:15 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #windows_fundamentals #infosec #windows_internals #tryhackme
ββββββββββββββββββββββββ
πͺ Author: Manmath somure
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 20 Mar 2026 13:34:15 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #windows_fundamentals #infosec #windows_internals #tryhackme
Medium
TryHackMe β Windows Fundamentals (Part II) Writeup
π§ Introduction
β€· Title: Hunting for Module Stomping Targets
ββββββββββββββββββββββββ
πͺ Author: Tom O'Neill
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 19 Jun 2026 11:42:53 GMT
ββββββββββββββββββββββββ
β Tags: #red_team #malware #hacking #cybersecurity #windows_internals
ββββββββββββββββββββββββ
πͺ Author: Tom O'Neill
ββββββββββββββββββββββββ
β΄΅ Time: Fri, 19 Jun 2026 11:42:53 GMT
ββββββββββββββββββββββββ
β Tags: #red_team #malware #hacking #cybersecurity #windows_internals
Medium
Hunting for Module Stomping Targets
Swapping Guesswork for Process-Specific Precision
β€· Title: The Single-Primitive Write: WriteProcessMemoryβs Hidden Page Flip
ββββββββββββββββββββββββ
πͺ Author: Tom O'Neill
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 21 Jun 2026 22:15:43 GMT
ββββββββββββββββββββββββ
β Tags: #malware #windows_internals #ethical_hacking #cybersecurity #windows
ββββββββββββββββββββββββ
πͺ Author: Tom O'Neill
ββββββββββββββββββββββββ
β΄΅ Time: Sun, 21 Jun 2026 22:15:43 GMT
ββββββββββββββββββββββββ
β Tags: #malware #windows_internals #ethical_hacking #cybersecurity #windows
Medium
The Single-Primitive Write: WriteProcessMemoryβs Hidden Page Flip
Documenting Undocumented WriteProcessMemory Behavior
β€· Title: Beyond the APIs: A Windows Internals Deep Dive into Process Injection
ββββββββββββββββββββββββ
πͺ Author: Ron Epstein
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 29 Jun 2026 18:00:19 GMT
ββββββββββββββββββββββββ
β Tags: #infosec #red_team #windows_internals #malware #cybersecurity
ββββββββββββββββββββββββ
πͺ Author: Ron Epstein
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 29 Jun 2026 18:00:19 GMT
ββββββββββββββββββββββββ
β Tags: #infosec #red_team #windows_internals #malware #cybersecurity
Medium
Beyond the APIs: A Windows Internals Deep Dive into Process Injection
A Windows internals deep dive into process injection. Explore VAD trees, page tables, and memory structures behind stealth execution.
β€· Title: Userland ALPC Enumeration: Dynamic & PPL-Aware Approach
ββββββββββββββββββββββββ
πͺ Author: Talha Nazeef Ahmed
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 21 Jul 2026 10:20:37 GMT
ββββββββββββββββββββββββ
β Tags: #windows_internals #reverse_engineering #infosec #cybersecurity #malware_analysis
ββββββββββββββββββββββββ
πͺ Author: Talha Nazeef Ahmed
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 21 Jul 2026 10:20:37 GMT
ββββββββββββββββββββββββ
β Tags: #windows_internals #reverse_engineering #infosec #cybersecurity #malware_analysis
Medium
Userland ALPC Enumeration: Dynamic & PPL-Aware Approach
Walking through ALPC from userland: avoiding hardcoded object indices, resolving query hangs, handling PPL boundries & verifying viaβ¦
β€· Title: Introduction to Section Headers and Sections (PE) β NIR(10)
ββββββββββββββββββββββββ
πͺ Author: NIRVANA
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 28 Jul 2026 06:26:01 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #malware #hacking #malware_development #windows_internals
ββββββββββββββββββββββββ
πͺ Author: NIRVANA
ββββββββββββββββββββββββ
β΄΅ Time: Tue, 28 Jul 2026 06:26:01 GMT
ββββββββββββββββββββββββ
β Tags: #cybersecurity #malware #hacking #malware_development #windows_internals
Medium
Introduction to Section Headers and Sections (PE) β NIR(10)
In our previous blog, we explored the Optional Header and Data Directory in detail. Now, itβs time to move forward and dive into Sectionβ¦