RSSAmplifier

Blog

Fluxsec.red Blog

RSS feed for fluxsec.red blog posts

fluxsec.redRSS feed ↗53 posts

Latest posts

Reverse engineering what HyperGuard monitors in ntoskrnl

Crimes against NTDLL - Implementing Early Cascade Injection

Introducing System Call Integrity Layer

Creating a Rust VBS Enclave DLL running in VTL1

Detecting Vectored Exception Handling Squared in an EDR

Vectored Exception Handling Squared

Creating a framework in Wyrm C2 to easily configure custom exports of an implant

Creating a local self signed certificate for localhost testing of Wyrm C2

Disassembly notes

Using Ghidriff to look at heap buffer overflow example

Timestomping a PE compile timestamp - adversary tradecraft and detection

Improving consistency with EDR DLL Injection via APCs

Hells Hollow: A new SSDT Hooking technique

Inside DCHSpy: Analysing Iranian APT MuddyWater free VPN mobile spyware

Rust OPSEC for Malware Development

Alt Syscalls for Windows 11

Making improvements to the EDR DLL injection

Making improvements to the EDR DLL injection

Real-time Ransomware Detection Strategy

Full spectrum Event Tracing for Windows detection in the kernel against rootkits

Reverse engineering undocumented Windows Kernel features to work with the EDR

Monitoring NTDLL for in memory patching

Intro and plan for the Sanctum EDR

Improving the Ghost Hunting implementation for flexibility and speed

Hells Gate Rust - EDR Evasion with syscalls

DLL Injection EDR Evasion 1: Hiding an elephant in the closet

EDR Evasion ETW patching in Rust

EDR Evasion APC Queue Injection in Rust

Reading Event Tracing for Windows Threat Intelligence

Windows Driver IRQL and acquiring a Driver Mutex

Error logging

Building the Driver Object

Configuring a Rust Windows driver

Creating a Windows Driver in Rust

Str Crypter - Payload string encryption with Rust

Rust DLL Search Order Hijacking

Export Resolver

Clipboard Hex Dumper Tool

Remote process DLL injection in Rust

Building a DLL in Rust

Introduction to the Windows API in Rust with a DLL Loader

Rust Windows Strings WinAPI Programming MSDN Cheatsheet

Creating a Protected Process Light in Rust for Sanctum EDR

Mitigating broadcast spoofs with Ghost Hunting

Hooking VirtualAllocEx

Ghost hunting OpenProcess

Communicating from the hooked syscall

Implementing syscall hooks in Rust

Theory: EDR Syscall hooking and Ghost Hunting, my approach to detection

wdk-mutex: An idiomatic mutex for Rust Windows Kernel Drivers