Slivering Through The Cracks
ID: 128202d0-315c-5969-8d7c-25c286f1ee25
STIX ID: report--128202d0-315c-5969-8d7c-25c286f1ee25
Feed Name: Binary Defense Blog
Threat Score
This report explains how the Sliver C2 framework implements NTDLL in-memory patching to remove security hooks and evade endpoint protections, dissects the RefreshPE() and writeGoodBytes() functions used to overwrite the .text section with a clean on-disk copy, and presents a telemetry-driven detection approach that flags these memory writes so defenders can build layered tripwires.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
