PurpleTeaming

  • Excuse Me, That’s My DLL (A Guide to DLL Hijacking Shenanigans)

    Excuse Me, That’s My DLL (A Guide to DLL Hijacking Shenanigans)

    Over the past few years, I’ve seen dozens of infection chains where adversaries relied on DLL hijacking as a core part of their toolkit. They did it because, until recently, these techniques easily bypassed most EDRs. Thankfully, defenses have improved. I’ve noticed EDRs are now much better at validating the paths where binaries run from,…

    read more