logo

Slivering Through The Cracks

ID: 128202d0-315c-5969-8d7c-25c286f1ee25

STIX ID: report--128202d0-315c-5969-8d7c-25c286f1ee25

Feed Name: Binary Defense Blog

Threat Score
60/100

Date Published: 2026-02-04

Date Updated: 2026-04-27

...
...

This report explains how the Sliver C2 framework implements NTDLL in-memory patching to remove security hooks and evade endpoint protections, dissects the RefreshPE() and writeGoodBytes() functions used to overwrite the .text section with a clean on-disk copy, and presents a telemetry-driven detection approach that flags these memory writes so defenders can build layered tripwires.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.