m.alvar.es

m.alvar.es

Tag

Windows

#windows

More content

Read more stories on Hashnode


Articles with this tag

[Anti-Analysis] Unhandled Exception Filters

Marcos AlvaresMarcos Alvares
Jan 14, 20261 min read

Abusing Unhandled Exception filters to detect debuggers · Here's another technique for my anti-analysis collection! It uses an Exception Handler and an...

[Anti-Analysis] Unhandled Exception Filters

[Cheatsheet] Userland WinDbg

Marcos AlvaresMarcos Alvares
Jan 11, 20261 min read

I do not need to use WinDbg for userland debugging that often BUT when I need to use it I REALLY need to use it! \O/ I keep forgetting some of the...

[Cheatsheet] Userland WinDbg

[Tool] Quick Snip to Detect ntdll.dll

Marcos AlvaresMarcos Alvares
Dec 31, 20251 min read

Recently, I’ve been reversing this first-stage that dynamically loads a copy of ntdll.dll in order to hide malicious behavior from Sandboxes and EDRs....

[Tool] Quick Snip to Detect ntdll.dll

©2026 m.alvar.es