>_dkom.dev
posts about rss

# injection

  • 2026.04.26 Process Injection Without the Obvious Thread: Early Bird APC and Beyond

    Why CreateRemoteThread+LoadLibraryA is immediately detectable, how Early Bird APC avoids the worst of the telemetry, and the injection techniques that push further into …

    windowsmalwareinjectionevasioninternals
© 2026 Emil Sorbroden / built with Hugo /rss