Notes
Research
Writeups and methods notes on VM-based obfuscation, hypervisors, hooking, and Windows internals, newest first.

Mouse, Keyboard, and the Path to WM_INPUT
Inside the Windows input path: RIM read completions, win32k sensor dispatch, mouse coordinate processing, keyboard state, and the two different ways applications consume Raw Input.
From a Window to Scanout: What BitBlt Actually Sees
A screenshot looks like a copy of whatever the GPU is sending to the monitor. Follow the surfaces through DXGI and DWM, and that assumption starts to fall apart.

How "Vigil" Was Built: A Unique Way of Hooking
Vigil watches PEB access without patching the code that reads it. The trick is a guarded fake PEB, a per-thread TEB swap, and a careful exception rearm path.

Building a Hypervisor-Assisted Emulator on Windows
WHP lets a normal usermode process build a tiny Hyper-V partition, run native code on the real CPU, and emulate the machine around it.

how undetected are "undetected" spoofers?
A look at a loud kernel spoofer that called itself "undetected", then attached itself to public device stacks, touched ETW-visible paths, and left registry markers everywhere.

Hypervisors, SLAT, and EPT/NPT Detection
How EPT/NPT split-view hooks work, what common probes actually measure, and where hypervisor detection gets noisy.

Detecting SLAT-Based Hypervisor Hooks
A practical look at SLAT memory cloaking, split-view hooks, and the timing, TLB, PMU, SMM, and DMA signals that can expose them.

Intel Processor Trace: Hardware Coverage Without the Overhead
Intel PT records every branch your CPU takes, compresses it into a stream of packets, and dumps it directly to physical memory. No instrumentation, no source code required, roughly two percent overhead.

VMProtect Internals: Devirtualization (Part 6)
The end goal of all this analysis: recovering readable code from a virtualized binary. How devirtualization tools approach the problem and where they fail.

VMProtect Internals: The Mutation Engine (Part 5)
Virtualization gets a lot of attention but mutation is what makes the handlers themselves unrecognizable. Three protection modes, one mutation engine.

VMProtect Internals: The Virtual Machine (Part 4)
The packer and loader were just the setup. The real protection is the virtual machine that replaces your native code with custom bytecode.

VMProtect Internals: Integrity Checks and Anti-Debug (Part 3)
The loader does not just unpack and move on. It is checking itself, checking you, and checking the environment the entire time. I dug into all of it.

VMProtect Internals: The Runtime Loader (Part 2)
What happens in the first milliseconds after a packed binary starts. I walked through the loader stub that rebuilds the executable in memory.

VMProtect Internals: How It Packs Your Binary (Part 1)
I reversed VMProtect to see how it compresses PE sections with LZMA and rebuilds the binary around a decompression stub.
No posts match.
How we publish a third-party issue is on the disclosure page.