Blindage

Notes

Research

Writeups and methods notes on VM-based obfuscation, hypervisors, hooking, and Windows internals, newest first.

Windows2026-09-0720 min read

Mouse, Keyboard, and the Path to WM_INPUT

Inside the Windows input path: RIM read completions, win32k sensor dispatch, mouse coordinate processing, keyboard state, and the two different ways applications consume Raw Input.

Windows2026-09-0710 min read

From a Window to Scanout: What BitBlt Actually Sees

A screenshot looks like a copy of whatever the GPU is sending to the monitor. Follow the surfaces through DXGI and DWM, and that assumption starts to fall apart.

Windows2026-08-3014 min read

How "Vigil" Was Built: A Unique Way of Hooking

Vigil watches PEB access without patching the code that reads it. The trick is a guarded fake PEB, a per-thread TEB swap, and a careful exception rearm path.

Reverse Engineering2026-07-0724 min read

Building a Hypervisor-Assisted Emulator on Windows

WHP lets a normal usermode process build a tiny Hyper-V partition, run native code on the real CPU, and emulate the machine around it.

Reverse Engineering2026-06-2713 min read

how undetected are "undetected" spoofers?

A look at a loud kernel spoofer that called itself "undetected", then attached itself to public device stacks, touched ETW-visible paths, and left registry markers everywhere.

Reverse Engineering2026-05-0252 min read

Hypervisors, SLAT, and EPT/NPT Detection

How EPT/NPT split-view hooks work, what common probes actually measure, and where hypervisor detection gets noisy.

Malware Analysis2026-05-0218 min read

Detecting SLAT-Based Hypervisor Hooks

A practical look at SLAT memory cloaking, split-view hooks, and the timing, TLB, PMU, SMM, and DMA signals that can expose them.

Reverse Engineering2026-03-1628 min read

Intel Processor Trace: Hardware Coverage Without the Overhead

Intel PT records every branch your CPU takes, compresses it into a stream of packets, and dumps it directly to physical memory. No instrumentation, no source code required, roughly two percent overhead.

Reverse Engineering2026-03-1116 min read

VMProtect Internals: Devirtualization (Part 6)

The end goal of all this analysis: recovering readable code from a virtualized binary. How devirtualization tools approach the problem and where they fail.

Reverse Engineering2026-03-1113 min read

VMProtect Internals: The Mutation Engine (Part 5)

Virtualization gets a lot of attention but mutation is what makes the handlers themselves unrecognizable. Three protection modes, one mutation engine.

Reverse Engineering2026-03-1115 min read

VMProtect Internals: The Virtual Machine (Part 4)

The packer and loader were just the setup. The real protection is the virtual machine that replaces your native code with custom bytecode.

Reverse Engineering2026-03-1114 min read

VMProtect Internals: Integrity Checks and Anti-Debug (Part 3)

The loader does not just unpack and move on. It is checking itself, checking you, and checking the environment the entire time. I dug into all of it.

Reverse Engineering2026-03-1112 min read

VMProtect Internals: The Runtime Loader (Part 2)

What happens in the first milliseconds after a packed binary starts. I walked through the loader stub that rebuilds the executable in memory.

Reverse Engineering2026-03-1110 min read

VMProtect Internals: How It Packs Your Binary (Part 1)

I reversed VMProtect to see how it compresses PE sections with LZMA and rebuilds the binary around a decompression stub.

How we publish a third-party issue is on the disclosure page.