9Hackers
Methodology About
  • BYOVD — Bring Your Own Vulnerable Driver with RTCore64

    Aug 31, 2026

    Notes — RTCore64 IOCTLs as WinDbg dq/eb from usermode.

  • Protected Process Light (PPL) — A WinDbg Deep Dive

    Aug 24, 2026

    WinDbg notes — find EPROCESS.Protection and zero it.

  • ETW Threat Intelligence — How Windows Watches Process Injection

    Aug 23, 2026

    WinDbg notes — find and disable the ETW-TI provider.

  • Kernel Callbacks — How EDRs See Every Process, Thread, and Image

    Aug 22, 2026

    WinDbg notes — enumerate and disable kernel callbacks.

9Hackers Offensive Security Research — kernel internals, offensive tooling, malware analysis.