<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>maldev wiki — recently updated</title><description>An open knowledge base for malware research — injection, evasion, persistence and C2, each technique paired with the detection logic that catches it.</description><link>https://maldev.thehackersbrain.dev</link><language>en</language><item><title>Process Hollowing</title><link>https://maldev.thehackersbrain.dev/techniques/injection/process-hollowing</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/injection/process-hollowing</guid><description>Replace the image of a suspended process before it ever executes.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>Process Injection</category><category>T1055.012</category><category>Windows</category><author>thehackersbrain</author></item><item><title>Sleep Obfuscation</title><link>https://maldev.thehackersbrain.dev/techniques/evasion/sleep-obfuscation</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/evasion/sleep-obfuscation</guid><description>Encrypt a beacon&apos;s own memory while it waits between check-ins, so scanners find nothing.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>Evasion &amp; Unhooking</category><category>T1027.007</category><category>Windows</category><author>thehackersbrain</author></item><item><title>Unhooking ntdll</title><link>https://maldev.thehackersbrain.dev/techniques/evasion/unhooking-ntdll</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/evasion/unhooking-ntdll</guid><description>Restore a clean copy of ntdll from disk to strip userland EDR hooks.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>Evasion &amp; Unhooking</category><category>T1562.001</category><category>Windows</category><author>thehackersbrain</author></item><item><title>Hunting Unbacked Executable Memory</title><link>https://maldev.thehackersbrain.dev/techniques/detection/unbacked-executable-memory</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/detection/unbacked-executable-memory</guid><description>The single highest-yield structural hunt across the whole injection category.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Blue Team &amp; Detection</category><category>T1055</category><category>Windows</category><author>thehackersbrain</author></item><item><title>Reflective DLL Loading</title><link>https://maldev.thehackersbrain.dev/techniques/injection/reflective-dll-loading</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/injection/reflective-dll-loading</guid><description>A DLL that maps itself — no LoadLibrary, no module list entry.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>Process Injection</category><category>T1620</category><category>Windows</category><author>thehackersbrain</author></item><item><title>COM Hijacking via TreatAs</title><link>https://maldev.thehackersbrain.dev/techniques/persistence/com-hijacking</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/persistence/com-hijacking</guid><description>Remap a system CLSID to your own object so a trusted process loads it for you.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>Persistence</category><category>T1546.015</category><category>Windows</category><author>thehackersbrain</author></item><item><title>Process Doppelgänging</title><link>https://maldev.thehackersbrain.dev/techniques/injection/process-doppelganging</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/injection/process-doppelganging</guid><description>Abuse NTFS transactions so the on-disk image never matches what runs.</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><category>Process Injection</category><category>T1055.013</category><category>Windows</category><author>thehackersbrain</author></item><item><title>Direct &amp; Indirect Syscalls</title><link>https://maldev.thehackersbrain.dev/techniques/evasion/direct-syscalls</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/evasion/direct-syscalls</guid><description>Skip the ntdll export table entirely by issuing the syscall instruction yourself.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><category>Evasion &amp; Unhooking</category><category>T1106</category><category>Windows</category><author>thehackersbrain</author></item><item><title>Thread Execution Hijacking</title><link>https://maldev.thehackersbrain.dev/techniques/injection/thread-execution-hijacking</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/injection/thread-execution-hijacking</guid><description>Suspend an existing thread, rewrite its context, point it at your shellcode.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate><category>Process Injection</category><category>T1055.003</category><category>Windows</category><author>thehackersbrain</author></item><item><title>Module Stomping</title><link>https://maldev.thehackersbrain.dev/techniques/injection/module-stomping</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/injection/module-stomping</guid><description>Overwrite the .text section of a benign loaded DLL so your code sits in backed memory.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>Process Injection</category><category>T1055.002</category><category>Windows</category><author>thehackersbrain</author></item><item><title>ptrace Injection</title><link>https://maldev.thehackersbrain.dev/techniques/injection/ptrace-injection</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/injection/ptrace-injection</guid><description>Attach to a live process on Linux and write shellcode straight into its address space.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>Process Injection</category><category>T1055.008</category><category>Linux</category><author>thehackersbrain</author></item><item><title>Classic DLL Injection</title><link>https://maldev.thehackersbrain.dev/techniques/injection/classic-dll-injection</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/injection/classic-dll-injection</guid><description>LoadLibrary in a remote thread. Trivially detected, but the baseline every other technique is measured against.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>Process Injection</category><category>T1055.001</category><category>Windows</category><author>thehackersbrain</author></item><item><title>APC Injection</title><link>https://maldev.thehackersbrain.dev/techniques/injection/apc-injection</link><guid isPermaLink="true">https://maldev.thehackersbrain.dev/techniques/injection/apc-injection</guid><description>Queue a user-mode APC onto an alertable thread and wait for it to drain.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>Process Injection</category><category>T1055.004</category><category>Windows</category><author>thehackersbrain</author></item></channel></rss>