5hidobu
  • About
Navigation bar avatar
  • AMSI bypuss 0x2

    This technique permit to force AmsiInitFailed via a null AmsiContext pointer invoking AmsiOpenSession. How can we detect this kind of technique? keep reading.

    Posted on August 23, 2023

    [Read More]
  • Akira Ransomware - NEO Tokyo is about to explode

    Brief analysis of the first version of the ransomware specimen used to ransom companies around the globe by the group named Akira.

    Posted on June 10, 2023

    [Read More]
  • AMSI bypuss 0x1

    AMSI stands for "Antimalware Scan Interface." This script essentially smashes the AMSI protection by breaking one of the components in the AMSI chain. How can we detect this kind of technique? keep reading.

    Posted on April 23, 2023

    [Read More]
  • Newer Posts
  • Email me
  • X (Twitter)
  • LinkedIn

5hid  •  2025  •  5hBlog.com

Powered by Beautiful Jekyll