Boot or Logon Autostart Execution (MITRE ATT&CK T1547)
Boot or Logon Autostart Execution is a persistence technique where an adversary configures malware or malicious scripts…
continue reading..
Image File Execution Options (IFEO) in Windows
1. What IFEO Really Is Image File Execution Options (IFEO) is a Windows kernel-supported execution redirection mechanism…
continue reading..
Sticky Keys Binary Hijacking: A Deep Technical Walkthrough
Sticky Keys binary hijacking is a classic Windows privilege escalation and persistence technique that abuses accessibility features…
continue reading..
Malware Obfuscation Techniques(T1027) in Cyber Security
Attackers hide or disguise malware, commands, or data so that security tools and analysts cannot easily detect…
continue reading..
Scheduled Task In Cyber Attack
1. What Are Scheduled Tasks (Windows Internals Perspective) Windows Scheduled Tasks are implemented via the Task Scheduler…
continue reading..
ClickFix Attacks: How One Click Turns Users into the Malware Installer
1. What Is ClickFix? ClickFix is a social engineering scam technique, not a virus by itself. It…
continue reading..
REvil/Sodinokibi – Ransomware a Detailed Explanation, IOCs
REvil (also known as Sodinokibi) is a financially motivated ransomware-as-a-service (RaaS) operation that emerged in 2019 and…
continue reading..
AiTM and the Future of MFA Bypass: How Attackers Are Exploiting Weaknesses in Authentication Systems
In December 2025, a new phishing and MFA bypass attack, called Adversary-in-the-Middle (AiTM), started targeting Microsoft 365…
continue reading..
Golden Tickets: Full Access to the Domain
What is a Golden Ticket? A Golden Ticket is a forged Kerberos Ticket Granting Ticket (TGT). This…
continue reading..
