Notes on Windows kernel internals, offensive tooling, and malware analysis.

Topics:

  • Kernel callback enumeration and removal
  • ETW Threat Intelligence
  • Protected Process Light (PPL)
  • BYOVD and vulnerable drivers