Beyond good ol’ Run key, Part 148
https://www.hexacorn.com/blog/2025/07/05/beyond-good-ol-run-key-part-148/
Red brain, Blue Fingers
Beyond good ol’ Run key, Part 148
https://www.hexacorn.com/blog/2025/07/05/beyond-good-ol-run-key-part-148/
Beyond good ol’ Run key, Part 147
https://www.hexacorn.com/blog/2025/07/05/beyond-good-ol-run-key-part-147/
@jernej__s same dir where the .exe is, as the .exe uses LoadLibrary (not LoadLibraryEx); so, if you copy the .exe to a diff. path and execute from there, it will work too
VMwareResolutionSet.exe VMwareResolutionSet.dll lolbin
https://www.hexacorn.com/blog/2025/06/15/vmwareresolutionset-exe-vmwareresolutionset-dll-lolbin/
wermgr.exe boot offdmpsvc.dll lolbin
https://www.hexacorn.com/blog/2025/06/14/wermgr-exe-boot-offdmpsvc-dll-lolbin/
wpr.exe boottrace phantom dll axeonoffhelper.dll lolbin
https://www.hexacorn.com/blog/2025/06/14/wpr-exe-boottrace-phantom-dll-axeonoffhelper-dll-lolbin/
mscoree.dll, RunDll32ShimW lolbin
https://www.hexacorn.com/blog/2025/05/31/mscoree-dll-rundll32shimw-lolbin/
Shell32.dll, #44 lolbin
https://www.hexacorn.com/blog/2025/05/18/shell32-dll-44-lolbin/
Minority (forensic) report aka defending forward w/o hacking back
Malware Source code string extraction
https://www.hexacorn.com/blog/2025/03/30/malware-source-code-string-extraction/
Hunting for the warez & other dodgy stuff people install / download, part 2
Hunting for the warez & other dodgy stuff people install / download, part 1
Good Exports are real
https://www.hexacorn.com/blog/2025/02/22/good-exports-are-real/
Optimizing the regexes, or not
https://www.hexacorn.com/blog/2025/02/22/optimizing-the-regexes-or-not/
The rapidly changing geopolitics and its inevitable effect on cyber
Update your playbooks folks
EPT=Elongated Persistent Threat
Being a tool while using a tool
https://www.hexacorn.com/blog/2025/01/25/being-a-tool-while-using-a-tool/
Clean hash set - 12M rows
https://www.hexacorn.com/blog/2024/12/31/clean-hash-set-12m-rows/
Smuggling payloads and tools in, using WIM images
https://www.hexacorn.com/blog/2024/12/31/smuggling-payloads-and-tools-in-using-wim-images/