malware analysis
Nanga: Process Telemetry from the Syscall Layer
A kernel-driver approach to malware dynamic analysis that captures process telemetry below user-mode evasion, at the syscall layer.
Research / Topic archive
Research, walkthroughs, and field notes on rootkit.