πNew WriteupβοΈ
βββββββββββββββ
πDate: Wed, 03 May 2023 18:14:45 GMT
βββββββββββββββ
βοΈTitle: Malware Persistence via the Windows Registry.
βββββββββββββββ
πLink: https://medium.com/p/30ea5839dd0e
βββββββββββββββ
Tags: #cybersecurity #windows #software_development #windows_api #malware_analysis
βββββββββββββββ
πDate: Wed, 03 May 2023 18:14:45 GMT
βββββββββββββββ
βοΈTitle: Malware Persistence via the Windows Registry.
βββββββββββββββ
πLink: https://medium.com/p/30ea5839dd0e
βββββββββββββββ
Tags: #cybersecurity #windows #software_development #windows_api #malware_analysis
Medium
Malware Persistence via the Windows Registry.
Following on from last weeks article which went over how to look for key loggers on Windows by watching out for specific function names inβ¦
β€· Title: EDR Atlatma Teknikleri: User-Modeβda PEB ManipΓΌlasyonu
ββββββββββββββββββββββββ
πͺ Author: PΔ±nar TaΕgΔ±n
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 14 Jun 2025 18:10:27 GMT
ββββββββββββββββββββββββ
β Tags: #peb #cybersecurity #windows_api_hooking #windows
ββββββββββββββββββββββββ
πͺ Author: PΔ±nar TaΕgΔ±n
ββββββββββββββββββββββββ
β΄΅ Time: Sat, 14 Jun 2025 18:10:27 GMT
ββββββββββββββββββββββββ
β Tags: #peb #cybersecurity #windows_api_hooking #windows
Medium
EDR Atlatma Teknikleri: User-Modeβda PEB ManipΓΌlasyonu
PEB Nedir?
β€· Title: Understanding Windows API and its use in Malware analysis
ββββββββββββββββββββββββ
πͺ Author: OluwapelumiOyerinde
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 19 Jun 2025 04:02:40 GMT
ββββββββββββββββββββββββ
β Tags: #windows_10 #cybersecurity #windows_api #malware #malware_analysis
ββββββββββββββββββββββββ
πͺ Author: OluwapelumiOyerinde
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 19 Jun 2025 04:02:40 GMT
ββββββββββββββββββββββββ
β Tags: #windows_10 #cybersecurity #windows_api #malware #malware_analysis
Medium
Understanding Windows API and its use in Malware analysis
What seems like harmless system calls may signal an attackβββsee how malware uses APIs for file access, DLL injection, and code execution.
β€· Title: DbgNexum: Shellcode injection using the Windows Debugging API
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 05 Jan 2026 03:32:19 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #Cyber Security 2026 #DbgNexum #EDR evasion #Hardware Breakpoints #Malware Research #Process injection #red teaming #shellcode #Windows API
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Mon, 05 Jan 2026 03:32:19 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #Cyber Security 2026 #DbgNexum #EDR evasion #Hardware Breakpoints #Malware Research #Process injection #red teaming #shellcode #Windows API
Penetration Testing Tools
DbgNexum: Shellcode injection using the Windows Debugging API
DbgNexum is a 2026 PoC that uses Hardware Breakpoints and File Mapping to inject shellcode without standard APIs, making it invisible to most EDRs.
β€· Title: The API Assassin: How βLOLAPIβ Unmasks the Native Commands Turning Windows and Cloud Against You
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Feb 2026 04:10:58 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #.NET reflection #API abuse #AWS #Azure #Cloud metadata #COM objects #cyber security news 2026 #GCP #Living_off_the_land #LOLAPI #Magic Claw #Windows API #WMI
ββββββββββββββββββββββββ
πͺ Author: ddos
ββββββββββββββββββββββββ
β΄΅ Time: Thu, 05 Feb 2026 04:10:58 +0000
ββββββββββββββββββββββββ
β Tags: #Open Source Tool #.NET reflection #API abuse #AWS #Azure #Cloud metadata #COM objects #cyber security news 2026 #GCP #Living_off_the_land #LOLAPI #Magic Claw #Windows API #WMI
Penetration Testing Tools
The API Assassin: How "LOLAPI" Unmasks the Native Commands Turning Windows and Cloud Against You
Magic Clawβs LOLAPI repository catalogs over 50 native Windows and Cloud APIs used by hackers to bypass WDAC and EDR. See the 2026 guide to stealthy API abuse.