corpus.blog
Most cited
Talked about
Blogs
54,302 blogs · [ { "id": "01a0821a-f74f-7216-9ec5-04f4e51c6f3a", "title": "Abusing .NET Core CLR Diagnostic Features (+ CVE-2023-33127)", "url": "https://bohops.com/2023/11/27/abusing-net-core-clr-diagnostic-features-cve-2023-33127/", "published_at": "2023-11-27T12:51:30+00:00" }, { "id": "01a0821a-f74f-7216-9ec5-04f4e51f4bfe", "title": "No Alloc, No Problem: Leveraging Program Entry Points for Process Injection", "url": "https://bohops.com/2023/06/09/no-alloc-no-problem-leveraging-program-entry-points-for-process-injection/", "published_at": "2023-06-09T00:53:46+00:00" }, { "id": "01a0821a-f74f-7216-9ec5-04f4e542efa0", "title": "Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion (Part 2)", "url": "https://bohops.com/2022/08/22/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion-part-2/", "published_at": "2022-08-22T23:48:27+00:00" }, { "id": "01a0821a-f74f-7216-9ec5-04f4e5f4a738", "title": "Unmanaged Code Execution with .NET Dynamic PInvoke", "url": "https://bohops.com/2022/04/02/unmanaged-code-execution-with-net-dynamic-pinvoke/", "published_at": "2022-04-02T16:45:49+00:00" }, { "id": "01a0821a-f74f-7216-9ec5-04f4e651df25", "title": "Analyzing and Detecting a VMTools Persistence Technique", "url": "https://bohops.com/2021/10/08/analyzing-and-detecting-a-vmtools-persistence-technique/", "published_at": "2021-10-08T03:42:18+00:00" }, { "id": "01a0821a-f74f-7216-9ec5-04f4e6a27a92", "title": "CVE-2021-0090: Intel Driver & Support Assistant (DSA) Elevation of Privilege (EoP)", "url": "https://bohops.com/2021/08/07/cve-2021-0090-intel-driver-support-assistant-dsa-elevation-of-privilege-eop/", "published_at": "2021-08-07T16:30:24+00:00" }, { "id": "01a0821a-f74f-7216-9ec5-04f4e741611d", "title": "Abusing and Detecting LOLBIN Usage of .NET Development Mode Features", "url": "https://bohops.com/2021/05/30/abusing-and-detecting-lolbin-usage-of-net-development-mode-features/", "published_at": "2021-05-30T16:24:30+00:00" }, { "id": "01a0821a-f74f-7216-9ec5-04f4e7c021a9", "title": "Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion", "url": "https://bohops.com/2021/03/16/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion/", "published_at": "2021-03-16T04:08:58+00:00" }, { "id": "01a0821a-f74f-7216-9ec5-04f4e8ac5b73", "title": "Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe", "url": "https://bohops.com/2020/11/02/exploring-the-wdac-microsoft-recommended-block-rules-part-ii-wfc-fsi/", "published_at": "2020-11-02T00:43:57+00:00" }, { "id": "01a0821a-f74f-7216-9ec5-04f4e8ddab2c", "title": "Exploring the WDAC Microsoft Recommended Block Rules: VisualUiaVerifyNative", "url": "https://bohops.com/2020/10/15/exploring-the-wdac-microsoft-recommended-block-rules-visualuiaverifynative/", "published_at": "2020-10-15T03:24:58+00:00" } ] posts
Claim your blog
Back to Bohops
Blog · corpus.blog/blogs/bohops.com/posts
Bohops
bohops.com
2023
Abusing .NET Core CLR Diagnostic Features (+ CVE-2023-33127)
original ↗
27 Nov 2023
No Alloc, No Problem: Leveraging Program Entry Points for Process Injection
original ↗
9 Jun 2023
2022
Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion (Part 2)
original ↗
22 Aug 2022
Unmanaged Code Execution with .NET Dynamic PInvoke
original ↗
2 Apr 2022
2021
Analyzing and Detecting a VMTools Persistence Technique
original ↗
8 Oct 2021
CVE-2021-0090: Intel Driver & Support Assistant (DSA) Elevation of Privilege (EoP)
original ↗
7 Aug 2021
Abusing and Detecting LOLBIN Usage of .NET Development Mode Features
original ↗
30 May 2021
Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion
original ↗
16 Mar 2021
2020
Exploring the WDAC Microsoft Recommended Block Rules (Part II): Wfc.exe, Fsi.exe, and FsiAnyCpu.exe
original ↗
2 Nov 2020
Exploring the WDAC Microsoft Recommended Block Rules: VisualUiaVerifyNative
original ↗
15 Oct 2020