Experimenting with PowerShell

PowerShell is typically preinstalled on modern Windows desktop and server platforms. If it is not present, you can download and install it by searching for **Windows Management Fr…

PowerShell EventLog CmdLets

PowerShell provides built-in **EventLog cmdlets** for collecting and inspecting Windows event logs. The most commonly used cmdlet is **Get-EventLog**, which retrieves events from …

Winsock fd_set Structure 0x104 Signature

# Winsock fd_set Structure (0x104 Signature) On 32-bit Windows, the `fd_set` structure from Winsock (`winsock2.h`) is exactly 260 bytes, or `0x104`. That makes `0x104` a useful s…

Debugger attach and ASLR rebasing pitfalls

# Debugger attach and ASLR rebasing pitfalls When attaching a debugger to a live Windows process, the static disassembly addresses shown in tools like [[Binary Ninja]] are usuall…

Firewall Service Filter

A **Service Filter** in Windows Firewall with Advanced Security is a rule property that limits a firewall rule to traffic associated with a specific Windows service. Instead of ap…