Click here to download all references as Bib-File.

Enter keywords to filter the library entries below or Propose new Entry
2023-04-19SophosAndreas Klopsch
‘AuKill’ EDR killer malware abuses Process Explorer driver
AuKill
2022-12-13SophosAndreas Klopsch, Andrew Brandt
Signed driver malware moves up the software trust chain
KillAV
2022-10-04SophosAndreas Klopsch
Remove All The Callbacks – BlackByte Ransomware Disables EDR Via RTCore64.sys Abuse
BlackByte
2022-05-04SophosAndreas Klopsch
Attacking Emotet’s Control Flow Flattening
Emotet
2021-08-22Malware and StuffAndreas Klopsch
PEB: Where Magic Is Stored
Dacls
2021-01-24malwareandstuff blogAndreas Klopsch
Catching Debuggers with Section Hashing
2020-07-12Malware and StuffAndreas Klopsch
Deobfuscating DanaBot’s API Hashing
DanaBot
2020-06-21Malware and StuffAndreas Klopsch
UpnP – Messing up Security since years
QakBot
2020-06-10GdataAndreas Klopsch
Harmful Logging - Diving into MassLogger
MASS Logger
2020-05-24Malware and StuffAndreas Klopsch
Examining Smokeloader’s Anti Hooking technique
SmokeLoader
2020-05-05Malware and StuffAndreas Klopsch
An old enemy – Diving into QBot part 3
QakBot
2020-03-30Malware and StuffAndreas Klopsch
An old enemy – Diving into QBot part 1
QakBot
2020-03-22Malware and StuffAndreas Klopsch
Mustang Panda joins the COVID-19 bandwagon
Cobalt Strike