-
Excuse Me, That’s My DLL (A Guide to DLL Hijacking Shenanigans)
Over the past few years, I’ve seen dozens of infection chains where adversaries relied on DLL hijacking as a core part of their toolkit. They did it because,…
4 min read
-
CertiGhostbusters! – Notes about detecting CVE-2026-54121 AD CS exploitation
CVE-2026-54121 – CertiGhost CVE-2026-54121, also known as “Certighost”, is a critical improper-authorization vulnerability in Microsoft Active Directory Certificate Services (AD CS) that allows a low-privileged domain user to…
4 min read


