
Driver-HideKernelThread-IoCancelIrp
Windows kernel driver technique that hides kernel threads by abusing IoCancelIrp and IRP cancel routines, with detection methods for identifying…
binary-analysisdefensive-toolsmalware-analysis+1

Windows kernel driver technique that hides kernel threads by abusing IoCancelIrp and IRP cancel routines, with detection methods for identifying…

Panic button for protection against cold boot attacks

PowerShell-based Intune remediation package that detects and removes the vulnerable autofstx.exe BootExecute entry from offline WinRE images, then…

Behave! A monitoring browser extension for pages acting as "bad boi"