2026-03-07 About NTFS and MFT Parsing Windows-Internal, Malware-Development IntroductionThe topic of Window NT File System ( NTFS ) is not new in the DFIR world, the ability to directly parsing o
2025-12-04 Where does my APC function go ? Windows-Internal, Malware-Development Windows IntroductionEarly-bird injection used to be every malware author’s favorite technique to bypass Windows defender ( a lon