[ ARCHIVE ]

Author: global_author

// Threats

Yara-Yara

Yara-Yara-Yara! 🐧 Now that we've sorted out strings, we can move on to generating byte signatures. Usually people try to make them as rarely as possible, since…

global_author
// Threats

Yara Yara Daze

Yara Yara Daze Anyone involved in malware analysis is certainly familiar with a tool like YARA 😉. With its help, many companies 🔴 build sets of signature rules…

global_author
// Detection

[SCCM NTLM Relay]

[SCCM NTLM Relay] Hello everyone! 👋 My article about SCCM attacks was recently published. It describes in sufficient detail the testing lab, the attacks themsel…

global_author
// Threats

Do you automate debugging?

Do you automate debugging? 🧐 The PT Sandbox expert team often has to debug various Windows kernel components in their work, and a kernel debugger is indispensab…

global_author