Skip to content

Search

Recent Posts

  • Callbacks Initialization & Identifying in Windows Kernel and Remove Callbacks with Windbg
  • Security of Handles & Misuse of DuplicateHandle

Categories

  • Uncategorized

Find Us

Address
123 Main Street
New York, NY 10001

Hours
Monday–Friday: 9:00AM–5:00PM
Saturday & Sunday: 11:00AM–3:00PM

  • About
  • Home
WinSysCall
WinSysCall
WinSysCall
WinSysCall
  • Home
  • About

Callbacks Initialization & Identifying in Windows Kernel and Remove Callbacks with Windbg

When discussing callbacks, most people often think of EDRs (Endpoint Detection and Response systems).There are numerous methods available for identifying callbacks in research environments. One such method was addressed by...
Mehrshad_MollaafzalJan 18, 2025Jan 18, 2025

Security of Handles & Misuse of DuplicateHandle

While writing practice code for a driver in windows, I discovered a security issue: It seemed there was a flaw in the DuplicateHandle function. I started investigating this issue and...
Mehrshad_MollaafzalJan 2, 2025Jan 18, 2025