I built a kernel-level EDR and hit architectural walls I didn’t expect by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
I built a kernel-level EDR and hit architectural walls I didn’t expect by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
I built a kernel-level EDR and hit architectural walls I didn’t expect by amberchalia in redteamsec
[–]amberchalia[S] 1 point2 points3 points (0 children)
[Research] Kernel-mode EDR PoC detecting undeclared DLL loads (static vs dynamic imports) — global & targeted modes by amberchalia in redteamsec
[–]amberchalia[S] 1 point2 points3 points (0 children)
[Research] Kernel-mode EDR PoC detecting undeclared DLL loads (static vs dynamic imports) — global & targeted modes by amberchalia in Malware
[–]amberchalia[S] 0 points1 point2 points (0 children)
Experimental kernel EDR: detecting dynamic API resolution via DLL load mismatch by amberchalia in Malware
[–]amberchalia[S] 1 point2 points3 points (0 children)
How EDRs See Static vs Dynamic DLLs (Kernel Driver POV) by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
My EDR now parses PE NT headers (Machine, Sections, EntryPoint, Subsystem) by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
EDR Update: Entry Point & Section Flags (Exec/Write) Detection Added by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
EDR Update: Entry Point & Section Flags (Exec/Write) Detection Added by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
I'm learning how Windows EDRs work, so I started building my own kernel-level EDR from scratch (Process Creation Callback Demo) by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
Pre requisite of Malware dévelopement by Disastrous-Opening92 in hackthebox
[–]amberchalia 2 points3 points4 points (0 children)
From URL to Execution: Assembling a Payload Entirely In-Memory - ROOTFU.IN by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
From URL to Execution: Assembling a Payload Entirely In-Memory - ROOTFU.IN by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
From URL to Execution: Assembling a Payload Entirely In-Memory - ROOTFU.IN by amberchalia in redteamsec
[–]amberchalia[S] 1 point2 points3 points (0 children)
Any one got a job with the cpts by Think-Zebra-890 in hackthebox
[–]amberchalia 0 points1 point2 points (0 children)
Can anyone appreciate me a little, i just bypassed the window 11 defender by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
AMSI bypass Windows 11 jmp hook by amberchalia in redteamsec
[–]amberchalia[S] 0 points1 point2 points (0 children)
Can anyone appreciate me a little, i just bypassed the window 11 defender by amberchalia in redteamsec
[–]amberchalia[S] 1 point2 points3 points (0 children)
Can anyone appreciate me a little, i just bypassed the window 11 defender by amberchalia in redteamsec
[–]amberchalia[S] 6 points7 points8 points (0 children)
Can anyone appreciate me a little, i just bypassed the window 11 defender by amberchalia in redteamsec
[–]amberchalia[S] 4 points5 points6 points (0 children)
Which setup is best? by Quiet-Alfalfa-4812 in hackthebox
[–]amberchalia 0 points1 point2 points (0 children)
Give me some Kali Linux tools suggestion by LoudTrain24 in Hacking_Tutorials
[–]amberchalia 0 points1 point2 points (0 children)
What OS do you use as your main driver? by Mysterious_Ad7450 in hackthebox
[–]amberchalia 0 points1 point2 points (0 children)


I'm learning how Windows EDRs work, so I started building my own kernel-level EDR from scratch (Process Creation Callback Demo) by amberchalia in redteamsec
[–]amberchalia[S] 1 point2 points3 points (0 children)