DetectionEngineering

  • Excuse Me, That’s My DLL (A Guide to DLL Hijacking Shenanigans)

    Excuse Me, That’s My DLL (A Guide to DLL Hijacking Shenanigans)

    Over the past few years, I’ve seen dozens of infection chains where adversaries relied on DLL hijacking as a core part of their toolkit. They did it because, until recently, these techniques easily bypassed most EDRs. Thankfully, defenses have improved. I’ve noticed EDRs are now much better at validating the paths where binaries run from,…

    read more

  • CertiGhostbusters! – Notes about detecting CVE-2026-54121 AD CS exploitation

    CertiGhostbusters! – Notes about detecting CVE-2026-54121 AD CS exploitation

    CVE-2026-54121 – CertiGhost CVE-2026-54121, also known as “Certighost”, is a critical improper-authorization vulnerability in Microsoft Active Directory Certificate Services (AD CS) that allows a low-privileged domain user to achieve full domain takeover. It was patched on July 14, 2026 Patch Tuesday updates, and a Proof of Concept was released 10 days later on Github by…

    read more