Latest posts
-
Building High-Fidelity YARA Rules for Obfuscated Memory Payloads

Practical techniques for identifying byte patterns and structural signatures inside unbacked executable memory regions.
-
Bypassing User-Land API Hooks via Direct System Calls

An examination of user-space telemetry injection inside NTDLL and how direct syscall stubs circumvent inline memory hooks.
-
Analyzing Kernel Callback Hooking in Modern EDR Drivers

A technical breakdown of how Endpoint Detection and Response drivers leverage kernel routines to monitor process creation and thread execution in real time.