Published October 9, 2025 | Version v5
Book Open

Attack and Defense: Ring -3 to Ring 3

Authors/Creators

Description

 

Table of Contents

  • Chapter 1: Attack and Defense: Ring -3 to Ring 3

  • Chapter 2: Bypassing API Monitoring - Technical Analysis of Direct Syscalls

  • Chapter 3: Process Manipulation - Modern Hollowing and Masquerading Techniques

  • Chapter 4: Advanced Memory Obfuscation – Nano Entropy Pulses and Spoofed Sections

  • Chapter 5: Execution Beyond Monitoring – Abusing Interrupt Request Level (IRQL)

  • Chapter 6: The Ultimate Hiding Place – Code Storage in Memory-Mapped I/O (MMIO)

  • Chapter 7: Immortal Persistence – Code Injection into UEFI/SPI Flash Firmware

  • Chapter 8: Introduction: The Invisible Orchestrator – Abusing System Management Mode (SMM)

  • Chapter 9: C2 through Remote Telemetry Channels – Abusing ETW and WNF

  • Chapter 10: C2 via Common Administrative and Network Protocols

  • Chapter 11: Network Traffic Obfuscation – Domain Fronting and Anti-Entropy Beaconing

  • Chapter 12: A New Detection Philosophy – Weak Signal Correlation

  • Chapter 13: Endpoint Hardening – A Bottom-Up Approach

  • Chapter 14: The Invisible Arms Race: Research and Development Directions in Cybersecurity

  • Chapter 15: New Behavioral Side-Channel – Data Encoding Through Virtual Mouse Movements (CursorHoppingEncoder)

  • Chapter 16: The Operating System’s “Dead Drop” – Abusing SRUM for Covert Communication Channels

  • Legal Disclaimer

Files

Book.pdf

Files (1.8 MB)

Name Size Download all
md5:6fcf395c346159400dc165cf8cb02489
1.8 MB Preview Download