Red Team
Offensive security research - malware development, EDR evasion, credential theft, and adversary tradecraft notes.

Latest
Detecting Avast CyberCapture Using Strings In Memory
Detect Avast CyberCapture by scanning process memory for distinctive strings as a companion technique to window-class checks.
Read post ->Series
Series in this section

Avast CyberCapture
Techniques for detecting Avast CyberCapture sandboxes through window classes and distinctive strings in process memory.

EDR-Evasive Profile Stealer
Architecture, build-time backends, bypass methods, and extraction techniques (Windows off-screen, CDP, Linux Ozone) for an EDR-evasive Chromium profile stealer research series.
Standalone
Standalone posts
Creating Fake Windows 11 Credential Popups with Google and EdgeShowcasing how to create fake Windows 11 credential popups only using a Chromium browser and a basic TCP listener. Research notes from Drew Alleman on...
Dumping Enterprise Chrome Policies Using Device Management Tokens from Verbose LogsI'll walk through post-compromise enumeration techniques to extract valuable information from verbose Chrome logs. Research notes from Drew Alleman on...
Building a Keylogger for Windows in C++This project is for educational purposes only. I built it to better understand how low-level keyboard input works in Windows and to prepare for writing...
Injecting Shellcode into Processes and Bypassing Windows DefenderA blogpost showcasing code to inject obfuscated shellcode into a windows process and techniques to avoid windows defender