Blog

Security operations write-ups, threat research and incident response.

  • From Intrusion Analysis to HijackLibs: DLL Sideloading Research

    This write-up covers my DLL sideloading research and recent contributions to HijackLibs, including an investigation where a legitimate, signed VMware binary, vmware-vmx.exe, was renamed and used to load a malicious libcrypto-3-x64.dll from the same directory.