Skip to content
RSS
Amplifier
Blogs
Podcasts
Music
Videos
Topics
Submit
Discover
Search
OPML
llms.txt
About
Sign up
Favorites
Account
Blog
Fluxsec.red Blog
RSS feed for fluxsec.red blog posts
fluxsec.red ↗
RSS feed ↗
53 posts
Follow
rust
edr
windows
dll
injection
creating
detection
dll injection
driver
edr evasion
evasion
ghost
Latest posts
Reverse engineering what HyperGuard monitors in ntoskrnl
Jul 26, 2026
Crimes against NTDLL - Implementing Early Cascade Injection
Mar 14, 2026
Introducing System Call Integrity Layer
Jan 17, 2026
Creating a Rust VBS Enclave DLL running in VTL1
Jan 15, 2026
Detecting Vectored Exception Handling Squared in an EDR
Jan 11, 2026
Vectored Exception Handling Squared
Dec 27, 2025
Creating a framework in Wyrm C2 to easily configure custom exports of an implant
Nov 23, 2025
Creating a local self signed certificate for localhost testing of Wyrm C2
Nov 17, 2025
Disassembly notes
Nov 15, 2025
Using Ghidriff to look at heap buffer overflow example
Nov 1, 2025
Timestomping a PE compile timestamp - adversary tradecraft and detection
Oct 26, 2025
Improving consistency with EDR DLL Injection via APCs
Oct 12, 2025
Hells Hollow: A new SSDT Hooking technique
Jul 28, 2025
Inside DCHSpy: Analysing Iranian APT MuddyWater free VPN mobile spyware
Jul 21, 2025
Rust OPSEC for Malware Development
May 31, 2025
Alt Syscalls for Windows 11
May 11, 2025
Making improvements to the EDR DLL injection
Apr 27, 2025
Making improvements to the EDR DLL injection
Apr 23, 2025
Real-time Ransomware Detection Strategy
Apr 6, 2025
Full spectrum Event Tracing for Windows detection in the kernel against rootkits
Mar 30, 2025
Reverse engineering undocumented Windows Kernel features to work with the EDR
Mar 4, 2025
Monitoring NTDLL for in memory patching
Mar 2, 2025
Intro and plan for the Sanctum EDR
Feb 7, 2025
Improving the Ghost Hunting implementation for flexibility and speed
Feb 6, 2025
Hells Gate Rust - EDR Evasion with syscalls
Feb 2, 2025
DLL Injection EDR Evasion 1: Hiding an elephant in the closet
Feb 2, 2025
EDR Evasion ETW patching in Rust
Feb 2, 2025
EDR Evasion APC Queue Injection in Rust
Feb 2, 2025
Reading Event Tracing for Windows Threat Intelligence
Feb 2, 2025
Windows Driver IRQL and acquiring a Driver Mutex
Dec 20, 2024
Error logging
Dec 10, 2024
Building the Driver Object
Nov 3, 2024
Configuring a Rust Windows driver
Oct 20, 2024
Creating a Windows Driver in Rust
Oct 20, 2024
Str Crypter - Payload string encryption with Rust
Oct 6, 2024
Rust DLL Search Order Hijacking
Oct 6, 2024
Export Resolver
Jun 4, 2024
Clipboard Hex Dumper Tool
Apr 22, 2024
Remote process DLL injection in Rust
Apr 1, 2024
Building a DLL in Rust
Mar 21, 2024
Introduction to the Windows API in Rust with a DLL Loader
Mar 20, 2024
Rust Windows Strings WinAPI Programming MSDN Cheatsheet
Feb 6, 2024
Creating a Protected Process Light in Rust for Sanctum EDR
Feb 1, 2024
Mitigating broadcast spoofs with Ghost Hunting
Jan 30, 2024
Hooking VirtualAllocEx
Jan 26, 2024
Ghost hunting OpenProcess
Jan 25, 2024
Communicating from the hooked syscall
Jan 19, 2024
Implementing syscall hooks in Rust
Jan 16, 2024
Theory: EDR Syscall hooking and Ghost Hunting, my approach to detection
Jan 16, 2024
wdk-mutex: An idiomatic mutex for Rust Windows Kernel Drivers
Jan 8, 2024
←
Prev
✦
Random
Next
→
Visit
↗
Feed
Kagi
↗