41554 blogs · [ { "id": "01a08778-e062-7361-8645-b4b1602ea507", "title": "Reverse engineering what HyperGuard monitors in ntoskrnl", "url": "https://fluxsec.red/what-does-hyperguard-skpg-monitor-vtl1-windows-internals-secure-kernel-patch-guard", "published_at": "2026-07-26T12:55:00+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15f390533", "title": "Crimes against NTDLL - Implementing Early Cascade Injection", "url": "https://fluxsec.red/implementing-early-cascade-injection-rust", "published_at": "2026-03-14T12:50:00+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15e42b6ab", "title": "Starting point for simple ransomware detection", "url": "https://fluxsec.red/simple-ransomware-detection-sanctum-minifilter", "published_at": "2026-02-15T05:40:00+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15dcbdb8f", "title": "Introducing System Call Integrity Layer", "url": "https://fluxsec.red/introducing-system-call-integrity-layer", "published_at": "2026-01-17T13:59:15+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15cfc6b05", "title": "Creating a Rust VBS Enclave DLL running in VTL1", "url": "https://fluxsec.red/creating-a-rust-application-running-in-vtl1", "published_at": "2026-01-15T19:15:45+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15c6275ab", "title": "Detecting Vectored Exception Handling Squared in an EDR", "url": "https://fluxsec.red/detecting-vectored-exception-handling-malware-rust-edr-windows-kernel", "published_at": "2026-01-11T13:40:45+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15c06dbf2", "title": "Vectored Exception Handling Squared", "url": "https://fluxsec.red/vectored-exception-handling-squared-rust", "published_at": "2025-12-27T19:09:45+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15b82f274", "title": "Creating a framework in Wyrm C2 to easily configure custom exports of an implant", "url": "https://fluxsec.red/creating-implant-dll-exports-wyrm-c2", "published_at": "2025-11-23T15:12:45+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15b3dc341", "title": "Creating a local self signed certificate for localhost testing of Wyrm C2", "url": "https://fluxsec.red/wyrm-c2-localhost-self-signed-certificate-windows", "published_at": "2025-11-17T19:09:12+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15ac2c24d", "title": "Disassembly notes", "url": "https://fluxsec.red/disassembly-notes", "published_at": "2025-11-15T08:36:17+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15a75f0b9", "title": "Using Ghidriff to look at heap buffer overflow example", "url": "https://fluxsec.red/using-ghidriff-to-examine-heap-buffer-overflow", "published_at": "2025-11-01T11:58:07+00:00" }, { "id": "01a08778-e062-7361-8645-b4b15a380e90", "title": "Timestomping a PE compile timestamp - adversary tradecraft and detection", "url": "https://fluxsec.red/timestomping-pe-compile-time", "published_at": "2025-10-26T09:02:59+00:00" }, { "id": "01a08778-e061-7066-a991-c10232f49fa3", "title": "Improving consistency with EDR DLL Injection via APCs", "url": "https://fluxsec.red/improving-EDR-via-windows-driver-apc-injection-rust", "published_at": "2025-10-12T14:10:51+00:00" }, { "id": "01a08778-e061-7066-a991-c10231fa88a2", "title": "Hells Hollow: A new SSDT Hooking technique", "url": "https://fluxsec.red/hells-hollow-a-new-SSDT-hooking-technique-with-alt-syscalls-rootkit", "published_at": "2025-07-28T19:57:18+00:00" }, { "id": "01a08778-e061-7066-a991-c10231bb57ee", "title": "Inside DCHSpy: Analysing Iranian APT MuddyWater free VPN mobile spyware", "url": "https://fluxsec.red/analysing-Iranian-APT-MuddyWater-mobile-spyware-free-vpn-comodo", "published_at": "2025-07-21T21:59:22+00:00" }, { "id": "01a08778-e061-7066-a991-c1023152e6c5", "title": "Rust OPSEC for Malware Development", "url": "https://fluxsec.red/rust-opsec-malware-development", "published_at": "2025-05-31T12:15:18+00:00" }, { "id": "01a08778-e061-7066-a991-c102314bb23b", "title": "Alt Syscalls for Windows 11", "url": "https://fluxsec.red/alt-syscalls-for-windows-11", "published_at": "2025-05-11T18:37:14+00:00" }, { "id": "01a08778-e061-7066-a991-c102310f2d61", "title": "Making improvements to the EDR DLL injection", "url": "https://fluxsec.red/early-bird-apc-queue-injection", "published_at": "2025-04-27T17:56:12+00:00" }, { "id": "01a08778-e061-7066-a991-c102303013ac", "title": "Making improvements to the EDR DLL injection", "url": "https://fluxsec.red/improving-edr-dll-injection-kernel-callback", "published_at": "2025-04-23T17:17:46+00:00" }, { "id": "01a08778-e061-7066-a991-c102302c435e", "title": "Real-time Ransomware Detection Strategy", "url": "https://fluxsec.red/considering-ransomware-edr-defence-strategy", "published_at": "2025-04-06T19:02:23+00:00" }, { "id": "01a08778-e061-7066-a991-c1022f57753f", "title": "Full spectrum Event Tracing for Windows detection in the kernel against rootkits", "url": "https://fluxsec.red/full-spectrum-event-tracing-for-windows-detection-in-the-kernel-against-rootkits", "published_at": "2025-03-30T17:21:42+00:00" }, { "id": "01a08778-e061-7066-a991-c1022e766efd", "title": "Reverse engineering undocumented Windows Kernel features to work with the EDR", "url": "https://fluxsec.red/reverse-engineering-windows-11-kernel", "published_at": "2025-03-04T18:28:19+00:00" }, { "id": "01a08778-e061-7066-a991-c1022de7f181", "title": "Monitoring NTDLL for in memory patching", "url": "https://fluxsec.red/monitoring-ntdll-for-memory-patching-etw-hacking-bypass-in-rust-EDR", "published_at": "2025-03-02T13:42:53+00:00" }, { "id": "01a08778-e061-7066-a991-c10224d60c89", "title": "Intro and plan for the Sanctum EDR", "url": "https://fluxsec.red/sanctum-edr-intro", "published_at": "2025-02-07T07:48:49+00:00" }, { "id": "01a08778-e061-7066-a991-c1022dad1467", "title": "Improving the Ghost Hunting implementation for flexibility and speed", "url": "https://fluxsec.red/improving-the-ghost-hunting-implementation-for-flexibility", "published_at": "2025-02-06T23:05:18+00:00" }, { "id": "01a08778-e061-7066-a991-c1021edeeddc", "title": "Hells Gate Rust - EDR Evasion with syscalls", "url": "https://fluxsec.red/rust-edr-evasion-hells-gate", "published_at": "2025-02-02T15:39:47+00:00" }, { "id": "01a08778-e061-7066-a991-c1021f29bee1", "title": "DLL Injection EDR Evasion 1: Hiding an elephant in the closet", "url": "https://fluxsec.red/dll-injection-edr-evasion-1", "published_at": "2025-02-02T15:39:47+00:00" }, { "id": "01a08778-e061-7066-a991-c1022409d00f", "title": "EDR Evasion ETW patching in Rust", "url": "https://fluxsec.red/etw-patching-rust", "published_at": "2025-02-02T15:39:47+00:00" }, { "id": "01a08778-e061-7066-a991-c10225381ab4", "title": "EDR Evasion APC Queue Injection in Rust", "url": "https://fluxsec.red/apc-queue-injection-rust", "published_at": "2025-02-02T15:39:47+00:00" }, { "id": "01a08778-e061-7066-a991-c1022d4c2e5a", "title": "Reading Event Tracing for Windows Threat Intelligence", "url": "https://fluxsec.red/event-tracing-for-windows-threat-intelligence-rust-consumer", "published_at": "2025-02-02T15:39:47+00:00" }, { "id": "01a08778-e061-7066-a991-c10227abe1cf", "title": "Windows Driver IRQL and acquiring a Driver Mutex", "url": "https://fluxsec.red/windows-rust-driver-irql-driver-mutex", "published_at": "2024-12-20T20:17:19+00:00" }, { "id": "01a08778-e061-7066-a991-c10227476ad9", "title": "Error logging", "url": "https://fluxsec.red/logging-errors-in-rust", "published_at": "2024-12-10T22:27:43+00:00" }, { "id": "01a08778-e061-7066-a991-c102273d5a26", "title": "Building the Driver Object", "url": "https://fluxsec.red/rust-windows-driver-object", "published_at": "2024-11-03T09:29:18+00:00" }, { "id": "01a08778-e061-7066-a991-c10226a8df35", "title": "Configuring a Rust Windows driver", "url": "https://fluxsec.red/rust-windows-driver-configuration", "published_at": "2024-10-20T10:12:43+00:00" }, { "id": "01a08778-e061-7066-a991-c102264a4077", "title": "Creating a Windows Driver in Rust", "url": "https://fluxsec.red/rust-windows-driver", "published_at": "2024-10-20T00:33:11+00:00" }, { "id": "01a08778-e061-7066-a991-c10222dbca1f", "title": "Str Crypter - Payload string encryption with Rust", "url": "https://fluxsec.red/str-crypter", "published_at": "2024-10-06T16:40:11+00:00" }, { "id": "01a08778-e061-7066-a991-c102254ff968", "title": "Rust DLL Search Order Hijacking", "url": "https://fluxsec.red/rust-dll-search-order-hijacking", "published_at": "2024-10-06T14:14:54+00:00" }, { "id": "01a08778-e061-7066-a991-c10223d2fe35", "title": "Export Resolver", "url": "https://fluxsec.red/export-resolver", "published_at": "2024-06-04T18:05:03+00:00" }, { "id": "01a08778-e061-7066-a991-c102229d4b9d", "title": "Clipboard Hex Dumper Tool", "url": "https://fluxsec.red/chx-copy-hex-dumper", "published_at": "2024-04-22T19:14:26+00:00" }, { "id": "01a08778-e061-7066-a991-c1021f2ed4aa", "title": "Remote process DLL injection in Rust", "url": "https://fluxsec.red/remote-process-dll-injection", "published_at": "2024-04-01T18:59:33+00:00" }, { "id": "01a08778-e061-7066-a991-c1021f963d65", "title": "Building a DLL in Rust", "url": "https://fluxsec.red/rust-dll-windows-api", "published_at": "2024-03-21T19:17:53+00:00" }, { "id": "01a08778-e061-7066-a991-c1022066d6fa", "title": "Introduction to the Windows API in Rust with a DLL Loader", "url": "https://fluxsec.red/winapi-rust-intro", "published_at": "2024-03-20T17:10:02+00:00" }, { "id": "01a08778-e061-7066-a991-c1022a787f70", "title": "Rust Windows Strings WinAPI Programming MSDN Cheatsheet", "url": "https://fluxsec.red/rust-windows-strings-winapi-programming-msdn-cheatsheet", "published_at": "2024-02-06T09:47:43+00:00" }, { "id": "01a08778-e061-7066-a991-c1022ca5c817", "title": "Creating a Protected Process Light in Rust for Sanctum EDR", "url": "https://fluxsec.red/creating-a-ppl-protected-process-light-in-rust-windows", "published_at": "2024-02-01T15:38:22+00:00" }, { "id": "01a08778-e061-7066-a991-c1022c2d8d00", "title": "Mitigating broadcast spoofs with Ghost Hunting", "url": "https://fluxsec.red/mitigating-broadcast-spoofing-rust-sanctum-edr-ghost-hunting", "published_at": "2024-01-30T19:34:43+00:00" }, { "id": "01a08778-e061-7066-a991-c1022bc4e57d", "title": "Hooking VirtualAllocEx", "url": "https://fluxsec.red/edr-hooking-virtual-alloc-ex-rust-malware", "published_at": "2024-01-26T14:29:19+00:00" }, { "id": "01a08778-e061-7066-a991-c1022b6f59df", "title": "Ghost hunting OpenProcess", "url": "https://fluxsec.red/ghost-hunting-open-process", "published_at": "2024-01-25T12:37:49+00:00" }, { "id": "01a08778-e061-7066-a991-c10229bee7f5", "title": "Communicating from the hooked syscall", "url": "https://fluxsec.red/communicating-from-hooked-syscall-rust", "published_at": "2024-01-19T21:42:52+00:00" }, { "id": "01a08778-e061-7066-a991-c10228f147a6", "title": "Implementing syscall hooks in Rust", "url": "https://fluxsec.red/implementing-syscall-hooking-rust", "published_at": "2024-01-16T22:45:52+00:00" }, { "id": "01a08778-e061-7066-a991-c102283d6c3f", "title": "Theory: EDR Syscall hooking and Ghost Hunting, my approach to detection", "url": "https://fluxsec.red/edr-syscall-hooking", "published_at": "2024-01-16T19:01:37+00:00" }, { "id": "01a08778-e061-7066-a991-c102280d506e", "title": "wdk-mutex: An idiomatic mutex for Rust Windows Kernel Drivers", "url": "https://fluxsec.red/wdk-mutex-windows-driver-mutex", "published_at": "2024-01-08T19:53:12+00:00" }, { "id": "01a08778-e061-7066-a991-c1022162df25", "title": "How I developed a markdown blog in Go and HTMX", "url": "https://fluxsec.red/how-I-developed-a-markdown-blog-with-go-and-HTMX", "published_at": "2023-12-25T07:52:52+00:00" }, { "id": "01a08778-e061-7066-a991-c102221e4fe4", "title": "Reflective DLL injection and bootstrapping in C", "url": "https://fluxsec.red/reflective-dll-injection-in-c", "published_at": "2023-01-06T19:08:52+00:00" } ] posts Claim your blog
Back to fluxsec.red
Blog · corpus.blog/blogs/fluxsec.red/posts

fluxsec.red

fluxsec.red

2026

2025

2024

2023