TrainSec source integration · directory
TrainSec Domains
Domain index for the permitted TrainSec Knowledge Library mirrors. Use these cross-links to move between malware analysis, Windows internals, hardware security, and related research.
Career guidance
2 articles
- Cybersecurity Salaries: How Much Can You Earn in Different Roles? · Uriel Kosayev
- Is Malware Analysis Right for You? · Uriel Kosayev
Hardware hacking
4 articles
- The Hitchhiker's Guide to Breaking Secure Boot · Amichai Yifrach
- Reinventing UART Security: Leveraging the Parity Bit for Robust Protection in OT Networks · Amichai Yifrach
- Trojan Horse Implementation in Hardware · Amichai Yifrach
- Best starter Hardware Hacking Toolkit · Amichai Yifrach
Malware analysis
20 articles
- Meet TrainSec Co-Founder Uriel Kosayev at DEF CON 34 · Uriel Kosayev
- Why Malware Analysts Need to Think Like Attackers · Uriel Kosayev
- Malware Analysis in the Age of AI: What Still Requires Human Skill? · Uriel Kosayev
- WannaCry Dropper Analysis: Itsy Bitsy Tricks That Break Your Tools · Uriel Kosayev
- The Complete Malware Analyst Roadmap: Step-by-Step Guide · Uriel Kosayev
- How Malware Really Works (What Most People Miss) · Uriel Kosayev
- MAoS – Malware Analysis on Steroids book released · Uriel Kosayev
- Reverse Engineering ARM based Mirai Botnet · Uriel Kosayev
- Dissecting the BlackByte Ransomware · Uriel Kosayev
- Debugging DLL Files with IDA Disassembler · Uriel Kosayev
- Celebrate Uriel Kosayev's Birthday with crazy price cuts! · Uriel Kosayev
- Back to the Future of the Cyber Landscape · Uriel Kosayev
- MuddyWater Initial Access Trojan · Uriel Kosayev
- One Electron to Rule Them All · Uriel Kosayev
- CrowdStrike and the Formidable BSOD · Pavel Yosifovich
- Intel® Audio Driver Unquoted Service Path Vulnerability · Uriel Kosayev
- MSI TrueColor Unquoted Service Path · Uriel Kosayev
- The Malware Shlayer · Uriel Kosayev
- Microsoft WslService Unquoted Service Path Vulnerability · Uriel Kosayev
- Dissecting Ardamax Keylogger · Uriel Kosayev
SOC & DFIR
4 articles
- You Can’t Sleep in the AI Era: The Brutal Reality of Securing Modern Data Centers · Uriel Kosayev
- Cyber & AI – Friend or Foe? Lessons from the Orange Systems Inspiration Session · Uriel Kosayev
- Two Sides of The Same Coin - From Dissected Malware to EDR Evasion · Uriel Kosayev
- Can Document Files Be Trusted? · Uriel Kosayev
Windows internals
36 articles
- VMMap Basics: How to Read a Windows Process's Memory Layout · Pavel Yosifovich
- Windows Privileges Explained: SeDebugPrivilege and AdjustTokenPrivileges in C++ · Pavel Yosifovich
- How Windows App Execution Aliases Work (and How to Read Them in C++) · Pavel Yosifovich
- DLL Injection with Windows Application Verifier · Pavel Yosifovich
- What Are Windows Logon Sessions and How Do They Relate to Tokens? · Pavel Yosifovich
- How to Embed and Extract Custom PE Resources in C++ · Pavel Yosifovich
- How Windows PE Files Use Custom Resources to Embed Anything · Pavel Yosifovich
- NTFS Transactions in Windows: Kernel Transaction Manager, CreateFileTransacted, and Process Doppelganging · Pavel Yosifovich
- Creating COM Objects with the Class Moniker (CoGetObject) · Pavel Yosifovich
- Capture ETW events with C++ (Part 2) · Pavel Yosifovich
- Capture ETW events with C++ (Part 1) · Pavel Yosifovich
- Writing Control Panel Applications · Pavel Yosifovich
- Hiding a Service with C++ · Pavel Yosifovich
- Hiding A Windows Service From Enumeration · Pavel Yosifovich
- Windows System Programming In Rust · Pavel Yosifovich
- Windows Research with WinDBG - 4H Live (7th April) masterclass with Pavel · Pavel Yosifovich
- Windows TLS (Thread-Local Storage) Explained · Pavel Yosifovich
- Looking into Windows Access Masks · Pavel Yosifovich
- How to Delete a File in Windows (and What “Delete” Really Means) · Pavel Yosifovich
- When Process Hollowing Isn’t Process Hollowing · Pavel Yosifovich
- AMSI Scanning in C#: P/Invoke, Memory-Mapped Files, and Safe Interop · Pavel Yosifovich
- How to scan files with the Anti-Malware Scan Interface in Windows? · Pavel Yosifovich
- Inside Windows Sessions: A Deep Dive with Pavel · Pavel Yosifovich
- How to Capture a Process Snapshot in Windows · Pavel Yosifovich
- Kernel Debugging Windows VMs – A Practical Walk-Through · Pavel Yosifovich
- Introduction to Windows Management Instrumentation (WMI) · Pavel Yosifovich
- Writing a Simple Key Logger · Pavel Yosifovich
- Running an Executable as SYSTEM: Unlocking Windows Privilege Escalation Techniques · Pavel Yosifovich
- Exploring the Blue Screen of Death: A Practical Deep Dive · Pavel Yosifovich
- Live Workshop: Attack and Defense: Remote Thread Injection and Detection (Recorded) · Uriel Kosayev
- Shell Icon Handler extension · Pavel Yosifovich
- Understanding the Differences Between CreateProcessAsUser and CreateProcessWithTokenW in Windows · Pavel Yosifovich
- Building a Simple RPC Client and Server: A Step-by-Step Guide · Pavel Yosifovich
- Exploring NTFS Alternate Streams: A Hidden Gem of the Windows File System · Pavel Yosifovich
- Introduction to the Windows Performance Analyzer (WPA) · Pavel Yosifovich
- “Application Types” on Windows · Pavel Yosifovich
Windows kernel
12 articles
- Windows Shell Links in C++: How to Read and Write .lnk Files · Pavel Yosifovich
- Launch WSL Applications from Windows with WslLaunch · Pavel Yosifovich
- Linked Lists in the Windows Kernel · Pavel Yosifovich
- How does Windows Subsystem for Linux (Version 1) actually work? · Pavel Yosifovich
- Kernel Allocation Tags in Windows Explained · Pavel Yosifovich
- Inside the Windows Recycle Bin - What Really Happens When You Delete a File? · Pavel Yosifovich
- Protected Processes & PPL: keeping Windows’ heart safe · Pavel Yosifovich
- Understanding RunDLL32: Leveraging Dynamic Function Invocation · Pavel Yosifovich
- Writing a Windows Service · Pavel Yosifovich
- Introduction to Windows Services · Pavel Yosifovich
- Sharing Kernel Objects by Name - Perks and Perils · Pavel Yosifovich
- Maximum Handles in a process · Pavel Yosifovich
Windows programming
6 articles
- How to Build a Process Tree in Windows with Code · Pavel Yosifovich
- Writing a WinDbg Extension: Streamline Your Debugging Workflow · Pavel Yosifovich
- Understanding UAC Virtualization: A Security Mechanism for Legacy Applications · Pavel Yosifovich
- Keyboard Hook with Image File Execution Options · Pavel Yosifovich
- Building a Process Tree · Pavel Yosifovich
- Code Injection with Image File Execution Options · Pavel Yosifovich