research

The stuff you came here for

Browse long-form research, lab observations, and implementation notes across malware development, EDR evasion, Windows internals, and Zig tooling.

EDR Evasion

3

edr-evasion / hooking / reverse-engineering

Malware Development

2

zig / malware-dev / tooling

Windows Internals

3

windows-internals / research

Offensive Engineering

3

red-team / offensive-security

analysisedr-evasionred-teamresearchsleep-obfuscationwindows-internalszig

featured research

Most Recent

zig 16 min

COMegon: Putting Beacons to Bed with COM Internals

Introducing COMegon — a sleep primitive that dispatches arbitrary API calls through the COM runtime's RPC machinery.

zig edr-evasion research windows-internals red-team
dossier read →

complete archive

All research notes

entry 02

Sleepy Beacons: A retrospective on how implants take naps

A walk through on how implant sleep-obfuscation evolved from naive Sleep() through Ekko and friends, why call-stack hunters forced stack spoofing, and how ETW Threat Intelligence plans to catch them all.

sleep-obfuscation windows-internals