Malware Development

DLL Notification Injection

New “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local and remote processes.

MalRDP: Implementing Rouge RDP Manually

Weaponizing RDP files for phishing and initial access. Based on the work of Mike Felch on Rouge RDP technique.

It’s all in the details: The curious case of an LSASS dumper gone undetected

Let me first start by saying I will not be revealing in this post any novel techniques or new research that hasn’t been seen before. I will, however, reveal my own methodology when it comes to finding gaps in EDRs visibility in order to bypass detection.

