Rrxnveerainrxnveera.blog·Aug 23 · 16 min readThe Complete Token Manipulation Playbook — Every Technique, One Truth About Parent PIDsFour remaining techniques, a debunked myth about SecLogon and svchost.exe, and the definitive comparison of every way to abuse Windows Access Tokens. Previously — Two Techniques Down In Part 1, we co41J
Rrxnveerainrxnveera.blog·Aug 16 · 13 min readThe Seclogon Shortcut — Spawning SYSTEM Processes via CreateProcessWithTokenWHow a built-in Windows service does the dirty work for you — converting Impersonation tokens to Primary tokens behind the scenes, letting you spawn processes as SYSTEM with fewer privileges and less c20
Rrxnveerainrxnveera.blog·Aug 8 · 17 min read Born With a Stolen Soul — Spawning Processes With Swapped Identities via NtSetInformationProcessHow we create a legitimate Windows process, replace its identity before it executes a single instruction, and wake it up as SYSTEM — invisible to most EDR process creation hooks. Introduction — What E00
Rrxnveerainrxnveera.blog·Jul 29 · 8 min readThe Silent Recon - Why Malware Authors Choose RID CyclingWhen an attacker lands a foothold on a Windows machine, their absolute first priority is discovery. They need to answer one crucial question: Who else is on this box? Finding local accounts—especially31N
Rrxnveerainrxnveera.blog·Jul 21 · 4 min readUnderstanding Process Isolation in WindowsLet's break down how two processes communicate in Windows, what process isolation means, and how APIs like WriteProcessMemory and VirtualAllocEx manage to access another process's memory — without bre00