Malware Development
Posts about malware development for offensive tradecraft. Usual disclaimer: don't be stupid.
Beyond NPPSPY: Harvesting Credentials and Bypassing AppLocker & WDAC via Windows Credential Provider Framework
Windows Process Cloning — How to dump a process without dumping the process
Ghostly Reflective PE Loader — how to make an existing remote process inject a PE in itself
Ghostly Hollowing — probably the most bizarre Windows process injection technique I know
How to write a local PE Loader from scratch (for educational purposes)
Voidgate: how to execute shellcode while keeping it encrypted
Using syscalls to bypass User-land EDR hooks
A Gentle Introduction to Syscalls in Windows
API hooking with Detours on Windows
IPFuscation — using IP addresses to obfuscate your sus payloads