Windows Internals

Who Needs Macros? | Threat Actors Pivot to Abusing Explorer and Other LOLBins via Windows Shortcuts

Aleksandar Milenkoski, Jim Walter

Inside Malicious Windows Apps for Malware Deployment

Aleksandar Milenkoski

The TPM: Technical Overview of Microsoft’s Interim Measures against CVE-2017-15361

Aleksandar Milenkoski

Device Guard Image Integrity: Function Invocation Paths between ci.dll and skci.dll

Aleksandar Milenkoski

Windows Defender Application Control: Image verification

Aleksandar Milenkoski

Windows Defender Application Control: Initialization

Dominik Phillips, Aleksandar Milenkoski

Device Guard Image Integrity: Architecture Overview

Aleksandar Milenkoski

Virtual Secure Mode: Initialization

Dominik Phillips, Aleksandar Milenkoski

Virtual Secure Mode: Protections of Communication Interfaces

Aleksandar Milenkoski

Virtual Secure Mode: Communication Interfaces

Aleksandar Milenkoski

Virtual Secure Mode: Architecture Overview

Aleksandar Milenkoski

ELAM: The Windows Defender ELAM Driver

Aleksandar Milenkoski

The TPM: Workflow of the Manual and Automatic TPM Provisioning Processes

Aleksandar Milenkoski

The TPM: Integrity Measurement

Aleksandar Milenkoski

The TPM: Communication Interfaces

Aleksandar Milenkoski