core-jmp core-jmpdeath of core jump

NTDLL Unhooking Rants: KnownDlls, VADs, and RWX Page Detection

A technical deep dive into NTDLL unhooking techniques using KnownDlls section mapping, Virtual Address Descriptors, and RWX page detection to bypass EDR hooks—covering Windows memory internals, kernel behavior, and practical code examples.

NTDLL Unhooking Rants: KnownDlls, VADs, and RWX Page Detection

0x01 // Recent research

all 317 posts →
1 2 19