{"version":1,"pages":[{"id":"thGYBNSln4C3UbSqiE16","title":"af6897cafc3603a5642fa4c5a1170473","pathname":"/ghostinthehive-as-a-ghost-in-the-hive","siteSpaceId":"sitesp_AzMBf","description":"_this blog is a work in progress_"},{"id":"DkwJwrKKmIp3aDidEQQE","title":"MuddyWater pt1: GHOSTBACKDOOR","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/tradecraft-analysis-defenders-catalogue/muddywater-pt1-ghostbackdoor","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Tradecraft Analysis - Defender's Catalogue"}]},{"id":"PQ9LtcXOp7W0uPTihBKg","title":"Reverse Engineering","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/reverse-engineering/reverse-engineering","siteSpaceId":"sitesp_AzMBf","breadcrumbs":[{"label":"Reverse Engineering"}]},{"id":"BFMZhOE0AnVgP6yVYfCD","title":"Disassemble that binary","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/reverse-engineering/reverse-engineering/disassemble-that-binary","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Reverse Engineering"},{"label":"Reverse Engineering"}]},{"id":"hGrxAvfSoX7mkQ83hKLr","title":"C Code constructs and Assembly Primer","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/reverse-engineering/reverse-engineering/c-code-constructs-and-assembly-premier","siteSpaceId":"sitesp_AzMBf","description":"WIP","breadcrumbs":[{"label":"Reverse Engineering"},{"label":"Reverse Engineering"}]},{"id":"dlbonqRQzKRazgvf7ZGK","title":"Dissecting a PE File","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/reverse-engineering/reverse-engineering/dissecting-a-pe-file","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Reverse Engineering"},{"label":"Reverse Engineering"}]},{"id":"ICd4fXTkR7OuEbvF8uRV","title":"Dissecting a PE File Format Data Directories p1 Imports Exports","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/reverse-engineering/reverse-engineering/dissecting-a-pe-file-format-data-directories-p1-imports-exports","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Reverse Engineering"},{"label":"Reverse Engineering"}]},{"id":"2jkZl5cznj9dSpd0wGc5","title":"Dissecting an ELF File","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/reverse-engineering/reverse-engineering/dissecting-an-elf-file","siteSpaceId":"sitesp_AzMBf","description":"WIP","breadcrumbs":[{"label":"Reverse Engineering"},{"label":"Reverse Engineering"}]},{"id":"QBndUv83xQAtiGysjmFH","title":"Windows Internals","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/windows-internals","siteSpaceId":"sitesp_AzMBf","breadcrumbs":[{"label":"Windows and Malware"}]},{"id":"ecqA2aLEvxhBomcJofwQ","title":"Windows APIs","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/windows-internals/windows-apis","siteSpaceId":"sitesp_AzMBf","description":"WIP - WINDOWS COMPONENTS: API / COM OBJECTS/ DEVELOPMENT COMPONENTS .. long article discussing windows components and how they are exploited in the wild.","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Windows Internals"}]},{"id":"XJGWHLndtloxgg5mn3Q2","title":"Malware Unpacking","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/windows-internals/malware-unpacking","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Windows Internals"}]},{"id":"Jfqi9Wsd0VujRA48GzqS","title":"Malware Evasion through Injection pt1","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/windows-internals/malware-evasion-through-injection-pt1","siteSpaceId":"sitesp_AzMBf","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Windows Internals"}]},{"id":"3RCSONbPQ8TwY0qjJItX","title":"Malware Evasion through Injection pt2","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/windows-internals/malware-evasion-through-injection-pt2","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Windows Internals"}]},{"id":"Uc2uePhrUejm9VoIe0CP","title":"Malware Evasion: Anti Analysis","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/windows-internals/malware-evasion-anti-analysis","siteSpaceId":"sitesp_AzMBf","description":"WIP","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Windows Internals"}]},{"id":"APjcrKsKERf3oIPl5RIq","title":"Malware Analysis","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/malware-dissecting","siteSpaceId":"sitesp_AzMBf","breadcrumbs":[{"label":"Windows and Malware"}]},{"id":"giaaxZ6T86abjpS3kr7r","title":"Unpacking Dridex","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/malware-dissecting/unpacking-dridex","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Malware Analysis"}]},{"id":"bNiclqQ1IDxaIkhTaTeR","title":"Unpacking SmokeLoader","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/malware-dissecting/unpacking-smokeloader","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Malware Analysis"}]},{"id":"zkmlGM2aorWfdCY5QSV3","title":"Unpacking Ramnit","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/malware-dissecting/unpacking-ramnit","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Malware Analysis"}]},{"id":"XqSMnK1O5cUuLGsLnsmr","title":"Unpacking Parallax","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/malware-dissecting/unpacking-parallax","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Malware Analysis"}]},{"id":"o13NgHWXWgRIPpS91Cvm","title":"Unpacking Osiris","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/malware-dissecting/unpacking-osiris","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Malware Analysis"}]},{"id":"ZgFhf3DqOMuNZojH2fAE","title":"Unpacking Zloader","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/malware-dissecting/unpacking-zloader","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Malware Analysis"}]},{"id":"M1l8FxCM3xlAMf83sQtF","title":"Heaven's gate and all the goodies","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/windows-and-malware/malware-dissecting/heavens-gate-and-all-the-goodies","siteSpaceId":"sitesp_AzMBf","description":"","breadcrumbs":[{"label":"Windows and Malware"},{"label":"Malware Analysis"}]},{"id":"30Lxd0WJ8ha9skh88GGC","title":"Debugging the Linux Kernel with Qemu and GDB","pathname":"/ghostinthehive-as-a-ghost-in-the-hive/debugging-the-linux-kernel-with-qemu-and-gdb","siteSpaceId":"sitesp_AzMBf","description":""}]}