Writeups

Coming Soon

This section will host deep-dive DFIR case studies and step-by-step investigations.

First up: LSASS shellcode case study.

Posts

Dissecting Process Hollowing - Rogue LSASS with Injected Shellcode
DFIR · Memory Forensics
EDR-Freeze – Forensic Analysis of an EDR Coma Attack
DFIR · Memory Forensics