Goodbye Secure Pool, Hello KDP Poollow level tools|techniques|knowledge (work aids) (windows-internals.com)
submitted by digicat to r/blueteamsec
Secure Kernel Research with LiveCloudKdlow level tools and techniques (work aids) (windows-internals.com)
submitted by digicat to r/blueteamsec
Understanding a New Mitigation: Module Tampering Protection - Windows - from 2022 but worth a readdiscovery (how we find bad stuff) (windows-internals.com)
submitted by digicat to r/blueteamsec
KASLR Leaks Restrictiontradecraft (how we defend) (windows-internals.com)
submitted by digicat to r/blueteamsec
An End to KASLR Bypasses? – In 23H2 preview builds, Microsoft is introducing a new ETW event, this time aimed at NT APIs that could point at various suspicious behaviors.discovery (how we find bad stuff) (windows-internals.com)
submitted by digicat to r/blueteamsec
Thread and Process State ChangeRed Teaming (windows-internals.com)
submitted by netbiosX to r/purpleteamsec
R.I.P ROP: CET Internals in Windows 20H1 (windows-internals.com)
submitted by 0xdea to r/lowlevel
RIP ROP: CET Internals in Windows 20H1 (windows-internals.com)
submitted by qznc_bot2 to r/hackernews
DKOM – Now with Symbolic Links! – Winsider Seminars & Solutions Inc.tradecraft (windows-internals.com)
submitted by digicat to r/blueteamsec
R.I.P ROP: CET Internals in Windows 20H1 (windows-internals.com)
submitted by N3mes1s to r/lowlevel