Open in app

Sign in

Write

Sign in

Sohail Saha
Sohail Saha

88 followers

Home

About

OSEP in 2025 — experience, advice & criticism

OSEP is more of a marathon than a race. This post narrates my experience, contains advice for students, and a review of the course.

May 4
1
OSEP in 2025 — experience, advice & criticism
OSEP in 2025 — experience, advice & criticism
May 4
1

Windows Process Cloning — How to dump a process without dumping the process

That title isn’t an exagerration or wordplay. There is a way to dump a process without opening a read handle to it. Read on.

Apr 12
Windows Process Cloning — How to dump a process without dumping the process
Windows Process Cloning — How to dump a process without dumping the process
Apr 12

Ghostly Reflective PE Loader — how to make an existing remote process inject a PE in itself

How to combine reflective DLL injection with Ghostly hollowing to make an existing remote process inject a PE in itself.

Mar 11
Ghostly Reflective PE Loader — how to make an existing remote process inject a PE in itself
Ghostly Reflective PE Loader — how to make an existing remote process inject a PE in itself
Mar 11

Ghostly Hollowing — probably the most bizarre Windows process injection technique I know

That title is not an exaggeration. I was looking at remote process injection techniques I could use in my C2 — Hydrangea. That’s when I…

Mar 6
Ghostly Hollowing — probably the most bizarre Windows process injection technique I know
Ghostly Hollowing — probably the most bizarre Windows process injection technique I know
Mar 6

How to write a local PE Loader from scratch (for educational purposes)

This post takes you through the steps to write a custom PE loader that can load and execute a PE from straight from memory.

Dec 1, 2024
How to write a local PE Loader from scratch (for educational purposes)
How to write a local PE Loader from scratch (for educational purposes)
Dec 1, 2024

Certified Red Team Operator (CRTO) in 2024 — My review & tips

Yesterday I had successfully passed the CRTO exam. Today I received the above badge in my email. I want to document my whole experience…

Nov 24, 2024
1
Certified Red Team Operator (CRTO) in 2024 — My review & tips
Certified Red Team Operator (CRTO) in 2024 — My review & tips
Nov 24, 2024
1

Voidgate: how to execute shellcode while keeping it encrypted

Voidgate evades AV/EDRs by decrypting and executing only one instruction of encrypted shellcode at a time, before re-encrypting it back.

Sep 28, 2024
1
Voidgate: how to execute shellcode while keeping it encrypted
Voidgate: how to execute shellcode while keeping it encrypted
Sep 28, 2024
1

Using syscalls to bypass User-land EDR hooks

This post discusses direct and indirect syscalls, and showcases how to use this idea to bypass user-land EDR hooks.

Sep 17, 2024
Using syscalls to bypass User-land EDR hooks
Using syscalls to bypass User-land EDR hooks
Sep 17, 2024

A Gentle Introduction to Syscalls in Windows

This post introduces the concept of syscalls in Windows, and all the relevant prerequisite concepts — System services, SSDTs and SSNs.

Sep 17, 2024
A Gentle Introduction to Syscalls in Windows
A Gentle Introduction to Syscalls in Windows
Sep 17, 2024

API hooking with Detours on Windows

This is an introduction to the concept of API hooking, and the Detours library to hook WinAPI functions.

Sep 8, 2024
API hooking with Detours on Windows
API hooking with Detours on Windows
Sep 8, 2024
Sohail Saha

Sohail Saha

88 followers

Cybersec noob

Help

Status

About

Careers

Press

Blog

Privacy

Rules

Terms

Text to speech