Rrxnveerainrxnveera.blog·6d ago · 9 min readAdversary Simulation — Walking Through a Real Attack Chain, Stage by StageLet's break down what adversary simulation actually is, how a simulation team moves through an organization stage by stage, and how each of those stages maps to MITRE ATT&CK. What Is Adversary Simulat00
Rrxnveerainrxnveera.blog·Aug 23 · 16 min readThe Complete Token Manipulation Playbook — Every Technique, One Truth About Parent PIDsFour remaining techniques, a debunked myth about SecLogon and svchost.exe, and the definitive comparison of every way to abuse Windows Access Tokens. Previously — Two Techniques Down In Part 1, we co41J
Rrxnveerainrxnveera.blog·Aug 16 · 13 min readThe Seclogon Shortcut — Spawning SYSTEM Processes via CreateProcessWithTokenWHow a built-in Windows service does the dirty work for you — converting Impersonation tokens to Primary tokens behind the scenes, letting you spawn processes as SYSTEM with fewer privileges and less c20
Rrxnveerainrxnveera.blog·Aug 8 · 17 min read Born With a Stolen Soul — Spawning Processes With Swapped Identities via NtSetInformationProcessHow we create a legitimate Windows process, replace its identity before it executes a single instruction, and wake it up as SYSTEM — invisible to most EDR process creation hooks. Introduction — What E00
Rrxnveerainrxnveera.blog·Jul 29 · 8 min readThe Silent Recon - Why Malware Authors Choose RID CyclingWhen an attacker lands a foothold on a Windows machine, their absolute first priority is discovery. They need to answer one crucial question: Who else is on this box? Finding local accounts—especially31N