Demystifying Windows Internals — Part 1 of 2: Windows Threads
Common Information
Type Value
UUID 5fd44784-8c17-476c-8c0a-774b80db4dd4
Fingerprint f63c9957b7a41458
Analysis status DONE
Considered CTI value 0
Text language
Published June 30, 2023, 12:14 a.m.
Added to db June 30, 2023, 2:31 a.m.
Last updated Nov. 17, 2024, 7:44 p.m.
Headline Demystifying Windows Internals — Part 1 of 2: Windows Threads
Title Demystifying Windows Internals — Part 1 of 2: Windows Threads
Detected Hints/Tags/Attributes 63/2/19
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 167 Cybersecurity on Medium https://medium.com/feed/tag/cybersecurity 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 207
learn.microsoft.com
Details Domain 4127
github.com
Details Domain 4
0x00sec.org
Details Domain 2
scorpiosoftware.net
Details Domain 2
nasbench.medium.com
Details File 19
teams.exe
Details File 1
agent.msi
Details File 533
ntdll.dll
Details File 115
win32k.sys
Details File 172
dllhost.exe
Details File 1122
svchost.exe
Details File 478
lsass.exe
Details Github username 6
swiftonsecurity
Details Url 1
https://learn.microsoft.com/en-us/windows-hardware/drivers/gettingstarted/user-mode-and-kernel-mode
Details Url 3
https://github.com/swiftonsecurity/sysmon-config
Details Url 1
https://learn.microsoft.com/en-us/windows/win32/procthread/about-processes-and-threads
Details Url 1
https://0x00sec.org/t/process-injection-remote-thread-injection-or-createremotethread/24399
Details Url 1
https://scorpiosoftware.net/2021/07/03/processes-threads-and-windows
Details Url 1
https://nasbench.medium.com/windows-system-processes-an-overview-for-blue-teams-42fa7a617920