Latest Post
View all →Inside Event Tracing for Windows with EtwSuite
Event Tracing for Windows is one of Windows' richest telemetry systems. This video introduces the ETW ecosystem and shows how EtwSuite can turn raw provider events into practical security research and UAC-bypass detections.
Read post →
Open Source Projects
GitHub →Jormungandr
A kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.
View on GitHub →Nidhogg
Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.
View on GitHub →NovaHypervisor
Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compatible with VMware and Hyper-V.
View on GitHub →Cronos
A sleep obfuscation technique leveraging waitable timers to evade memory scanners.
View on GitHub →Sandman
An NTP-based backdoor for operations in hardened networks.
View on GitHub →Venom
A library performing evasive communication using a stolen browser socket.
View on GitHub →