<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://mooolight.github.io/</id><title>Cybersecurity Blog</title><subtitle>A blog about pentesting, red teaming and malware with a focus on Windows security research.</subtitle> <updated>2026-03-20T18:17:51+00:00</updated> <author> <name></name> <uri>https://mooolight.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://mooolight.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://mooolight.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>TryHackMe Certifications</title><link href="https://mooolight.github.io/TryHackMe-Certs/" rel="alternate" type="text/html" title="TryHackMe Certifications" /><published>2026-03-20T17:00:00+00:00</published> <updated>2026-03-20T17:00:00+00:00</updated> <id>https://mooolight.github.io/TryHackMe-Certs/</id> <content src="https://mooolight.github.io/TryHackMe-Certs/" /> <author> <name></name> </author> <category term="Cybersecurity" /> <summary> TryHackMe Certifications - Timeline (2022 - 2024) </summary> </entry> <entry><title>Reversing Ekko</title><link href="https://mooolight.github.io/Reversing-Ekko/" rel="alternate" type="text/html" title="Reversing Ekko" /><published>2025-06-19T17:00:00+00:00</published> <updated>2025-06-19T17:00:00+00:00</updated> <id>https://mooolight.github.io/Reversing-Ekko/</id> <content src="https://mooolight.github.io/Reversing-Ekko/" /> <author> <name></name> </author> <category term="Malware" /> <category term="Evasion" /> <summary> What is Ekko? Similar to Gargoyle, Ekko is a malware evasion technique as well that relies on a time window to wait before it modifies the payload’s memory region as executable again and then proceeding to actual execution instead of a detour. Reversing Ekko #include &amp;lt;windows.h&amp;gt; #include &amp;lt;stdio.h&amp;gt; #define _CRT_RAND_S #include &amp;lt;stdlib.h&amp;gt; #define NT_SUCCESS(Status) ((NTSTA... </summary> </entry> <entry><title>Reversing Gargoyle</title><link href="https://mooolight.github.io/Reversing-Gargoyle/" rel="alternate" type="text/html" title="Reversing Gargoyle" /><published>2025-05-29T17:00:00+00:00</published> <updated>2025-06-27T01:48:45+00:00</updated> <id>https://mooolight.github.io/Reversing-Gargoyle/</id> <content src="https://mooolight.github.io/Reversing-Gargoyle/" /> <author> <name></name> </author> <category term="Malware" /> <category term="Evasion" /> <summary> What is Gargoyle? Gargoyle is a malware evasion technique that hides in plain sight (from an AV perspective). Unlike traditional malware, Gargoyle understands that AVs and EDRs will trigger to do memory scanning given some suspicious event or action from a process which in this case is process injection. AVs will do memory scan on the suspicious process’ executable region which Gargoyle utiliz... </summary> </entry> <entry><title>Threat Hunting - Pivoting</title><link href="https://mooolight.github.io/Threat-Hunting-Pivoting/" rel="alternate" type="text/html" title="Threat Hunting - Pivoting" /><published>2024-09-19T05:00:00+00:00</published> <updated>2025-03-11T15:27:33+00:00</updated> <id>https://mooolight.github.io/Threat-Hunting-Pivoting/</id> <content src="https://mooolight.github.io/Threat-Hunting-Pivoting/" /> <author> <name></name> </author> <category term="TryHackMe" /> <category term="Threat Hunting" /> <summary> Questions: Is your organisation’s network robust enough to spot lateral movements of adversaries within your systems? Can you detect unusual network activities or illicit privilege escalation that could indicate a pivot attack? Can you use network telemetry and analytics to identify abnormal behaviour and halt lateral movement before it wreaks havoc? Example diagram: These are e... </summary> </entry> <entry><title>Threat Hunting; Hunt Me II - Typo Squatters</title><link href="https://mooolight.github.io/Threat-Hunting-Hunt-Me-II-Typo-Squatters/" rel="alternate" type="text/html" title="Threat Hunting; Hunt Me II - Typo Squatters" /><published>2024-09-19T05:00:00+00:00</published> <updated>2024-10-01T20:22:20+00:00</updated> <id>https://mooolight.github.io/Threat-Hunting-Hunt-Me-II-Typo-Squatters/</id> <content src="https://mooolight.github.io/Threat-Hunting-Hunt-Me-II-Typo-Squatters/" /> <author> <name></name> </author> <category term="TryHackMe" /> <category term="Threat Hunting" /> <summary> Hunt Me II - Typo Squatters </summary> </entry> </feed>
