[13/14] For the purpose this thread, I've assumed that the analyst does not have access to the scripts which call rundll32 and load the dll.
Those scripts are in the "scabs" folder, you can play around with them and potentially skip the first few steps of this thread 😃
[14/14] That's it for today 🖐️
I'm hoping to write some beginner-friendly on Ghidra and Debuggers in future. So leave a comment if there's any topics you'd be interested in reading about 📘
• • •
Missing some Tweet in this thread? You can try to
force a refresh