41554 blogs · [ { "id": "01a087ec-7b19-71f3-8c6c-9507619184e0", "title": "The Invisible Link: Inside the PE Header's Connection to PDBs", "url": "https://www.thecyberyeti.com/post/the-invisible-link-inside-the-pe-header-s-connection-to-pdbs", "published_at": "2025-11-24T04:36:42+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78ba52e87a0", "title": "Analyzing Shellcode with SCLauncher", "url": "https://www.thecyberyeti.com/post/analyzing-shellcode-with-sclauncher", "published_at": "2024-03-18T15:34:13+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78ba58f062e", "title": "Customizing FakeNet-NG's Default Web Root", "url": "https://www.thecyberyeti.com/post/customizing-fakenet-ng-s-default-web-root", "published_at": "2024-03-05T00:35:54+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78ba5c3ccc7", "title": "Identifying UserForms with Oledump and Olevba", "url": "https://www.thecyberyeti.com/post/identifying-userforms-with-oledump-and-olevba", "published_at": "2024-02-28T05:29:38+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78ba6b336fd", "title": "OneNote Malware: Hidden Payloads in Page Versions", "url": "https://www.thecyberyeti.com/post/onenote-malware-hidden-payloads-in-page-versions", "published_at": "2024-02-16T05:26:13+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78ba73cf64a", "title": "Anti-Analysis in JavaScript Executed by Windows Script Host (WSH)", "url": "https://www.thecyberyeti.com/post/anti-analysis-in-javascript-executed-by-windows-script-host-wsh", "published_at": "2024-02-11T15:43:50+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78ba80d9fff", "title": "Locating DLL Name from the Process Environment Block (PEB)", "url": "https://www.thecyberyeti.com/post/locating-dll-name-from-the-process-environment-block-peb", "published_at": "2024-02-10T15:33:24+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78ba892acdf", "title": "Exploring the Process Environment Block (PEB) with WinDbg", "url": "https://www.thecyberyeti.com/post/exploring-the-process-environment-block-peb-with-windbg", "published_at": "2024-02-10T15:29:09+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78ba8ca5c04", "title": "Maldoc Uses Template Injection for Macro Execution", "url": "https://www.thecyberyeti.com/post/maldoc-uses-template-injection-for-macro-execution", "published_at": "2024-02-08T06:01:32+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78ba9c2d462", "title": "How-To: Installing Oledump in Windows", "url": "https://www.thecyberyeti.com/post/how-to-installing-oledump-in-windows", "published_at": "2021-02-11T14:00:00+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78baaa2ecb0", "title": "Creating an IDA Python Plugin for Static XOR String Deobfuscation", "url": "https://www.thecyberyeti.com/post/creating-an-ida-python-plugin-for-static-xor-string-deobfuscation", "published_at": "2021-01-06T13:06:00+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78baac62b35", "title": "Emotet Maldoc Analysis – Embedded DLL and CertUtil for Base64 Decoding", "url": "https://www.thecyberyeti.com/post/emotet-maldoc-analysis-embedded-dll-and-certutil-for-base64-decoding", "published_at": "2020-12-02T11:31:00+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78baadd148f", "title": "Excel 4 Macros – Get.Workspace Reference", "url": "https://www.thecyberyeti.com/post/excel-4-macros-get-workspace-reference", "published_at": "2020-04-12T23:07:56+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78bab77d8c3", "title": "Removing Passwords from VBA Projects", "url": "https://www.thecyberyeti.com/post/removing-passwords-from-vba-projects", "published_at": "2020-04-09T14:08:10+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78bac5ed75e", "title": "Maldoc drops DLL and executes via ExecuteExcel4Macro", "url": "https://www.thecyberyeti.com/post/maldoc-drops-dll-and-executes-via-executeexcel4macro", "published_at": "2020-03-25T17:45:16+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78bad1b0e26", "title": "Maldoc uses Windows API to perform process hollowing", "url": "https://www.thecyberyeti.com/post/maldoc-uses-windows-api-to-perform-process-hollowing", "published_at": "2020-03-18T07:56:20+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78badfe5c40", "title": "Maldoc uses RC4 to hide PowerShell script, retrieves payload from DNS TXT record", "url": "https://www.thecyberyeti.com/post/maldoc-uses-rc4-to-hide-powershell-script-retrieves-payload-from-dns-txt-record", "published_at": "2020-03-10T09:12:23+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78bae2c3a93", "title": "Disabling Teredo IPv6 Tunnelling", "url": "https://www.thecyberyeti.com/post/disabling-teredo-ipv6-tunnelling", "published_at": "2020-02-29T14:30:12+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78baeceb981", "title": "Malware Analysis – Triaging Emotet (Fall 2019)", "url": "https://www.thecyberyeti.com/post/malware-analysis-triaging-emotet-fall-2019", "published_at": "2020-02-10T09:00:00+00:00" }, { "id": "01a087ec-7b1a-70d9-81d4-e78baf2860d3", "title": "How to Disable Microsoft Error Reporting", "url": "https://www.thecyberyeti.com/post/how-to-disable-microsoft-error-reporting", "published_at": "2020-01-26T23:14:02+00:00" } ] posts Claim your blog
Back to thecyberyeti.com
Blog · corpus.blog/blogs/thecyberyeti.com/posts

thecyberyeti.com

thecyberyeti.com

2025

2024

2021

2020