<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <atom:link href="https://fluxsec.red/rss.xml"
               rel="self"
               type="application/rss+xml"/>
    <title>Fluxsec.red Blog</title>
    <link>https://fluxsec.red/</link>
    <description>RSS feed for fluxsec.red blog posts</description>
    <lastBuildDate>Sat, 26 Apr 2025 12:00:00 GMT</lastBuildDate>
    <pubDate>Sat, 26 Apr 2025 12:00:00 GMT</pubDate>

    <item>
      <title>Hells Gate Rust - EDR Evasion with syscalls</title>
      <link>https://fluxsec.red/rust-edr-evasion-hells-gate</link>
      <guid>https://fluxsec.red/rust-edr-evasion-hells-gate</guid>
      <pubDate>Sun, 02 Feb 2025 15:39:47 GMT</pubDate>
    </item>

    <item>
      <title>DLL Injection EDR Evasion 1: Hiding an elephant in the closet</title>
      <link>https://fluxsec.red/dll-injection-edr-evasion-1</link>
      <guid>https://fluxsec.red/dll-injection-edr-evasion-1</guid>
      <pubDate>Sun, 02 Feb 2025 15:39:47 GMT</pubDate>
    </item>

    <item>
      <title>Remote process DLL injection in Rust</title>
      <link>https://fluxsec.red/remote-process-dll-injection</link>
      <guid>https://fluxsec.red/remote-process-dll-injection</guid>
      <pubDate>Mon, 01 Apr 2024 18:59:33 GMT</pubDate>
    </item>

    <item>
      <title>Building a DLL in Rust</title>
      <link>https://fluxsec.red/rust-dll-windows-api</link>
      <guid>https://fluxsec.red/rust-dll-windows-api</guid>
      <pubDate>Thu, 21 Mar 2024 19:17:53 GMT</pubDate>
    </item>

    <item>
      <title>Introduction to the Windows API in Rust with a DLL Loader</title>
      <link>https://fluxsec.red/winapi-rust-intro</link>
      <guid>https://fluxsec.red/winapi-rust-intro</guid>
      <pubDate>Wed, 20 Mar 2024 17:10:02 GMT</pubDate>
    </item>

    <item>
      <title>How I developed a markdown blog in Go and HTMX</title>
      <link>https://fluxsec.red/how-I-developed-a-markdown-blog-with-go-and-HTMX</link>
      <guid>https://fluxsec.red/how-I-developed-a-markdown-blog-with-go-and-HTMX</guid>
      <pubDate>Mon, 25 Dec 2023 07:52:52 GMT</pubDate>
    </item>

    <item>
      <title>Reflective DLL injection and bootstrapping in C </title>
      <link>https://fluxsec.red/reflective-dll-injection-in-c</link>
      <guid>https://fluxsec.red/reflective-dll-injection-in-c</guid>
      <pubDate>Fri, 06 Jan 2023 19:08:52 GMT</pubDate>
    </item>

    <item>
      <title>Clipboard Hex Dumper Tool</title>
      <link>https://fluxsec.red/chx-copy-hex-dumper</link>
      <guid>https://fluxsec.red/chx-copy-hex-dumper</guid>
      <pubDate>Mon, 22 Apr 2024 19:14:26 GMT</pubDate>
    </item>

    <item>
      <title>Str Crypter - Payload string encryption with Rust</title>
      <link>https://fluxsec.red/str-crypter</link>
      <guid>https://fluxsec.red/str-crypter</guid>
      <pubDate>Sun, 06 Oct 2024 16:40:11 GMT</pubDate>
    </item>

    <item>
      <title>Export Resolver</title>
      <link>https://fluxsec.red/export-resolver</link>
      <guid>https://fluxsec.red/export-resolver</guid>
      <pubDate>Tue, 04 Jun 2024 18:05:03 GMT</pubDate>
    </item>

    <item>
      <title>EDR Evasion ETW patching in Rust</title>
      <link>https://fluxsec.red/etw-patching-rust</link>
      <guid>https://fluxsec.red/etw-patching-rust</guid>
      <pubDate>Sun, 02 Feb 2025 15:39:47 GMT</pubDate>
    </item>

    <item>
      <title>Intro and plan for the Sanctum EDR</title>
      <link>https://fluxsec.red/sanctum-edr-intro</link>
      <guid>https://fluxsec.red/sanctum-edr-intro</guid>
      <pubDate>Fri, 07 Feb 2025 07:48:49 GMT</pubDate>
    </item>

    <item>
      <title>EDR Evasion APC Queue Injection in Rust</title>
      <link>https://fluxsec.red/apc-queue-injection-rust</link>
      <guid>https://fluxsec.red/apc-queue-injection-rust</guid>
      <pubDate>Sun, 02 Feb 2025 15:39:47 GMT</pubDate>
    </item>

    <item>
      <title>Rust DLL Search Order Hijacking</title>
      <link>https://fluxsec.red/rust-dll-search-order-hijacking</link>
      <guid>https://fluxsec.red/rust-dll-search-order-hijacking</guid>
      <pubDate>Sun, 06 Oct 2024 14:14:54 GMT</pubDate>
    </item>

    <item>
      <title>Creating a Windows Driver in Rust</title>
      <link>https://fluxsec.red/rust-windows-driver</link>
      <guid>https://fluxsec.red/rust-windows-driver</guid>
      <pubDate>Sun, 20 Oct 2024 00:33:11 GMT</pubDate>
    </item>

    <item>
      <title>Configuring a Rust Windows driver</title>
      <link>https://fluxsec.red/rust-windows-driver-configuration</link>
      <guid>https://fluxsec.red/rust-windows-driver-configuration</guid>
      <pubDate>Sun, 20 Oct 2024 10:12:43 GMT</pubDate>
    </item>

    <item>
      <title>Building the Driver Object</title>
      <link>https://fluxsec.red/rust-windows-driver-object</link>
      <guid>https://fluxsec.red/rust-windows-driver-object</guid>
      <pubDate>Sun, 03 Nov 2024 09:29:18 GMT</pubDate>
    </item>

    <item>
      <title>Error logging</title>
      <link>https://fluxsec.red/logging-errors-in-rust</link>
      <guid>https://fluxsec.red/logging-errors-in-rust</guid>
      <pubDate>Tue, 10 Dec 2024 22:27:43 GMT</pubDate>
    </item>

    <item>
      <title>Windows Driver IRQL and acquiring a Driver Mutex</title>
      <link>https://fluxsec.red/windows-rust-driver-irql-driver-mutex</link>
      <guid>https://fluxsec.red/windows-rust-driver-irql-driver-mutex</guid>
      <pubDate>Fri, 20 Dec 2024 20:17:19 GMT</pubDate>
    </item>

    <item>
      <title>wdk-mutex: An idiomatic mutex for Rust Windows Kernel Drivers</title>
      <link>https://fluxsec.red/wdk-mutex-windows-driver-mutex</link>
      <guid>https://fluxsec.red/wdk-mutex-windows-driver-mutex</guid>
      <pubDate>Mon, 08 Jan 2024 19:53:12 GMT</pubDate>
    </item>

    <item>
      <title>Theory: EDR Syscall hooking and Ghost Hunting, my approach to detection</title>
      <link>https://fluxsec.red/edr-syscall-hooking</link>
      <guid>https://fluxsec.red/edr-syscall-hooking</guid>
      <pubDate>Tue, 16 Jan 2024 19:01:37 GMT</pubDate>
    </item>

    <item>
      <title>Implementing syscall hooks in Rust</title>
      <link>https://fluxsec.red/implementing-syscall-hooking-rust</link>
      <guid>https://fluxsec.red/implementing-syscall-hooking-rust</guid>
      <pubDate>Tue, 16 Jan 2024 22:45:52 GMT</pubDate>
    </item>

    <item>
      <title>Communicating from the hooked syscall</title>
      <link>https://fluxsec.red/communicating-from-hooked-syscall-rust</link>
      <guid>https://fluxsec.red/communicating-from-hooked-syscall-rust</guid>
      <pubDate>Fri, 19 Jan 2024 21:42:52 GMT</pubDate>
    </item>

    <item>
      <title>Rust Windows Strings WinAPI Programming MSDN Cheatsheet</title>
      <link>https://fluxsec.red/rust-windows-strings-winapi-programming-msdn-cheatsheet</link>
      <guid>https://fluxsec.red/rust-windows-strings-winapi-programming-msdn-cheatsheet</guid>
      <pubDate>Tue, 06 Feb 2024 09:47:43 GMT</pubDate>
    </item>

    <item>
      <title>Ghost hunting OpenProcess</title>
      <link>https://fluxsec.red/ghost-hunting-open-process</link>
      <guid>https://fluxsec.red/ghost-hunting-open-process</guid>
      <pubDate>Thu, 25 Jan 2024 12:37:49 GMT</pubDate>
    </item>

    <item>
      <title>Hooking VirtualAllocEx</title>
      <link>https://fluxsec.red/edr-hooking-virtual-alloc-ex-rust-malware</link>
      <guid>https://fluxsec.red/edr-hooking-virtual-alloc-ex-rust-malware</guid>
      <pubDate>Fri, 26 Jan 2024 14:29:19 GMT</pubDate>
    </item>

    <item>
      <title>Mitigating broadcast spoofs with Ghost Hunting</title>
      <link>https://fluxsec.red/mitigating-broadcast-spoofing-rust-sanctum-edr-ghost-hunting</link>
      <guid>https://fluxsec.red/mitigating-broadcast-spoofing-rust-sanctum-edr-ghost-hunting</guid>
      <pubDate>Tue, 30 Jan 2024 19:34:43 GMT</pubDate>
    </item>

    <item>
      <title>Creating a Protected Process Light in Rust for Sanctum EDR</title>
      <link>https://fluxsec.red/creating-a-ppl-protected-process-light-in-rust-windows</link>
      <guid>https://fluxsec.red/creating-a-ppl-protected-process-light-in-rust-windows</guid>
      <pubDate>Thu, 01 Feb 2024 15:38:22 GMT</pubDate>
    </item>

    <item>
      <title>Reading Event Tracing for Windows Threat Intelligence</title>
      <link>https://fluxsec.red/event-tracing-for-windows-threat-intelligence-rust-consumer</link>
      <guid>https://fluxsec.red/event-tracing-for-windows-threat-intelligence-rust-consumer</guid>
      <pubDate>Sun, 02 Feb 2025 15:39:47 GMT</pubDate>
    </item>

    <item>
      <title>Improving the Ghost Hunting implementation for flexibility and speed</title>
      <link>https://fluxsec.red/improving-the-ghost-hunting-implementation-for-flexibility</link>
      <guid>https://fluxsec.red/improving-the-ghost-hunting-implementation-for-flexibility</guid>
      <pubDate>Thu, 06 Feb 2025 23:05:18 GMT</pubDate>
    </item>

    <item>
      <title>Monitoring NTDLL for in memory patching</title>
      <link>https://fluxsec.red/monitoring-ntdll-for-memory-patching-etw-hacking-bypass-in-rust-EDR</link>
      <guid>https://fluxsec.red/monitoring-ntdll-for-memory-patching-etw-hacking-bypass-in-rust-EDR</guid>
      <pubDate>Sun, 02 Mar 2025 13:42:53 GMT</pubDate>
    </item>

    <item>
      <title>Reverse engineering undocumented Windows Kernel features to work with the EDR</title>
      <link>https://fluxsec.red/reverse-engineering-windows-11-kernel</link>
      <guid>https://fluxsec.red/reverse-engineering-windows-11-kernel</guid>
      <pubDate>Tue, 04 Mar 2025 18:28:19 GMT</pubDate>
    </item>

    <item>
      <title>Full spectrum Event Tracing for Windows detection in the kernel against rootkits</title>
      <link>https://fluxsec.red/full-spectrum-event-tracing-for-windows-detection-in-the-kernel-against-rootkits</link>
      <guid>https://fluxsec.red/full-spectrum-event-tracing-for-windows-detection-in-the-kernel-against-rootkits</guid>
      <pubDate>Sun, 30 Mar 2025 17:21:42 GMT</pubDate>
    </item>

    <item>
      <title>Real-time Ransomware Detection Strategy</title>
      <link>https://fluxsec.red/considering-ransomware-edr-defence-strategy</link>
      <guid>https://fluxsec.red/considering-ransomware-edr-defence-strategy</guid>
      <pubDate>Sun, 06 Apr 2025 19:02:23 GMT</pubDate>
    </item>

    <item>
      <title>Making improvements to the EDR DLL injection</title>
      <link>https://fluxsec.red/improving-edr-dll-injection-kernel-callback</link>
      <guid>https://fluxsec.red/improving-edr-dll-injection-kernel-callback</guid>
      <pubDate>Wed, 23 Apr 2025 17:17:46 GMT</pubDate>
    </item>

    <item>
      <title>Making improvements to the EDR DLL injection</title>
      <link>https://fluxsec.red/early-bird-apc-queue-injection</link>
      <guid>https://fluxsec.red/early-bird-apc-queue-injection</guid>
      <pubDate>Sun, 27 Apr 2025 17:56:12 GMT</pubDate>
    </item>

    <item>
      <title>Alt Syscalls for Windows 11</title>
      <link>https://fluxsec.red/alt-syscalls-for-windows-11</link>
      <guid>https://fluxsec.red/alt-syscalls-for-windows-11</guid>
      <pubDate>Sun, 11 May 2025 18:37:14 GMT</pubDate>
    </item>

    <item>
      <title>Rust OPSEC for Malware Development</title>
      <link>https://fluxsec.red/rust-opsec-malware-development</link>
      <guid>https://fluxsec.red/rust-opsec-malware-development</guid>
      <pubDate>Sat, 31 May 2025 12:15:18 GMT</pubDate>
    </item>

    <item>
      <title>Inside DCHSpy: Analysing Iranian APT MuddyWater free VPN mobile spyware</title>
      <link>https://fluxsec.red/analysing-Iranian-APT-MuddyWater-mobile-spyware-free-vpn-comodo</link>
      <guid>https://fluxsec.red/analysing-Iranian-APT-MuddyWater-mobile-spyware-free-vpn-comodo</guid>
      <pubDate>Mon, 21 Jul 2025 21:59:22 GMT</pubDate>
    </item>

    <item>
      <title>Hells Hollow: A new SSDT Hooking technique</title>
      <link>https://fluxsec.red/hells-hollow-a-new-SSDT-hooking-technique-with-alt-syscalls-rootkit</link>
      <guid>https://fluxsec.red/hells-hollow-a-new-SSDT-hooking-technique-with-alt-syscalls-rootkit</guid>
      <pubDate>Mon, 28 Jul 2025 19:57:18 GMT</pubDate>
    </item>

    <item>
      <title>Improving consistency with EDR DLL Injection via APCs</title>
      <link>https://fluxsec.red/improving-EDR-via-windows-driver-apc-injection-rust</link>
      <guid>https://fluxsec.red/improving-EDR-via-windows-driver-apc-injection-rust</guid>
      <pubDate>Sun, 12 Oct 2025 14:10:51 GMT</pubDate>
    </item>

    <item>
      <title>Timestomping a PE compile timestamp - adversary tradecraft and detection</title>
      <link>https://fluxsec.red/timestomping-pe-compile-time</link>
      <guid>https://fluxsec.red/timestomping-pe-compile-time</guid>
      <pubDate>Sun, 26 Oct 2025 09:02:59 GMT</pubDate>
    </item>

    <item>
      <title>Using Ghidriff to look at heap buffer overflow example</title>
      <link>https://fluxsec.red/using-ghidriff-to-examine-heap-buffer-overflow</link>
      <guid>https://fluxsec.red/using-ghidriff-to-examine-heap-buffer-overflow</guid>
      <pubDate>Sat, 01 Nov 2025 11:58:07 Z</pubDate>
    </item>

    <item>
      <title>Disassembly notes</title>
      <link>https://fluxsec.red/disassembly-notes</link>
      <guid>https://fluxsec.red/disassembly-notes</guid>
      <pubDate>Sat, 15 Nov 2025 08:36:17 Z</pubDate>
    </item>

    <item>
      <title>Creating a local self signed certificate for localhost testing of Wyrm C2</title>
      <link>https://fluxsec.red/wyrm-c2-localhost-self-signed-certificate-windows</link>
      <guid>https://fluxsec.red/wyrm-c2-localhost-self-signed-certificate-windows</guid>
      <pubDate>Mon, 17 Nov 2025 19:09:12 Z</pubDate>
    </item>

    <item>
      <title>Creating a framework in Wyrm C2 to easily configure custom exports of an implant</title>
      <link>https://fluxsec.red/creating-implant-dll-exports-wyrm-c2</link>
      <guid>https://fluxsec.red/creating-implant-dll-exports-wyrm-c2</guid>
      <pubDate>Sun, 23 Nov 2025 15:12:45 Z</pubDate>
    </item>

    <item>
      <title>Vectored Exception Handling Squared</title>
      <link>https://fluxsec.red/vectored-exception-handling-squared-rust</link>
      <guid>https://fluxsec.red/vectored-exception-handling-squared-rust</guid>
      <pubDate>Sat, 27 Dec 2025 19:09:45 Z</pubDate>
    </item>

    <item>
      <title>Detecting Vectored Exception Handling Squared in an EDR</title>
      <link>https://fluxsec.red/detecting-vectored-exception-handling-malware-rust-edr-windows-kernel</link>
      <guid>https://fluxsec.red/detecting-vectored-exception-handling-malware-rust-edr-windows-kernel</guid>
      <pubDate>Sun, 11 Jan 2026 13:40:45 Z</pubDate>
    </item>

    <item>
      <title>Creating a Rust VBS Enclave DLL running in VTL1</title>
      <link>https://fluxsec.red/creating-a-rust-application-running-in-vtl1</link>
      <guid>https://fluxsec.red/creating-a-rust-application-running-in-vtl1</guid>
      <pubDate>Thu, 15 Jan 2026 19:15:45 Z</pubDate>
    </item>

    <item>
      <title>Introducing System Call Integrity Layer</title>
      <link>https://fluxsec.red/introducing-system-call-integrity-layer</link>
      <guid>https://fluxsec.red/introducing-system-call-integrity-layer</guid>
      <pubDate>Sat, 17 Jan 2026 13:59:15 Z</pubDate>
    </item>

    <item>
      <title>Starting point for simple ransomware detection</title>
      <link>https://fluxsec.red/simple-ransomware-detection-sanctum-minifilter</link>
      <guid>https://fluxsec.red/simple-ransomware-detection-sanctum-minifilter</guid>
      <pubDate>Sun, 8 Feb 2026 53:40:00 Z</pubDate>
    </item>

    <item>
      <title>Crimes against NTDLL - Implementing Early Cascade Injection</title>
      <link>https://fluxsec.red/implementing-early-cascade-injection-rust</link>
      <guid>https://fluxsec.red/implementing-early-cascade-injection-rust</guid>
      <pubDate>Sat, 14 Mar 2026 12:50:00 Z</pubDate>
    </item>

  </channel>https://fluxsec.red/disassembly-notes
</rss>