A fun investigation into EDR callback timing assumptions - www.originhq.com/blog/process...
Process Preluding: Child Process Injection Before The Story Begins | Origin
By John Uhlmann on 2026-02-17
originhq.com
John U
@jdu2600.bsky.social
He/him. Security Research Engineer @ Prelude Research.
A fun investigation into EDR callback timing assumptions - www.originhq.com/blog/process...
Process Preluding: Child Process Injection Before The Story Begins | Origin
By John Uhlmann on 2026-02-17
originhq.com
Passkeys provide an easier, faster and more secure way to log into online accounts than passwords.🗝️ Read more about how the NCSC is keeping pace with evolving technology⬇️ https://www.ncsc.gov.uk/collection/ncsc-annual-review-2025/chapter-03-keeping-pace-with-evolving-technology
Win32_Process has been the go to WMI class for remote command execution for years. Steven Flores explores a new WMI class that functions like Win32_Process and offers further capability. Read more: ghst.ly/4gyPbkr
More Fun With WMI - SpecterOps
TL;DR Win32_Process has been the go to WMI class for remote command execution for years. In this post we will cover a new WMI class that functions like Win32_Process and offers further capability From...
ghst.ly
Hey @sysinternals.com @markrussinovich.bsky.social How do I share information about a kernel bug that impacts Sysmon and Process Monitor?
"Writing Windows Unit Tests: Telemetry bugs are security vulnerabilities too" John Uhlmann reveals how flaws in Windows kernel telemetry can hide security risks, and why unit tests help fix them. Details: cfp.bsidescbr.com.au/bsides-canbe...
Writing Windows Unit Tests: Telemetry bugs are security vulnerabilities too BSides Canberra 2025
With the introduction of Kernel Patch Protection, Microsoft created a shared responsibility model where security vendors are now limited to only the kernel visibility and extension points that Microso...
cfp.bsidescbr.com.au
My final Elastic Security Labs blog - www.elastic.co/security-lab...
Call Stacks: No More Free Passes For Malware — Elastic Security Labs
We explore the immense value that call stacks bring to malware detection and why Elastic considers them to be vital Windows endpoint telemetry despite the architectural limitations.
elastic.co
We are removing default admin in Windows 11, get your apps ready now blogs.windows.com/windowsdevel...
Enhance your application security with administrator protection
Introduction Administrator protection is a new Windows 11 platform security feature that aims to protect the admin users on the device while still allowing them to perform the necessary functions whic...
blogs.windows.com
ATT&CK never felt quite right to me. I originally thought it was just that the taxonomy was incomplete. Then Jared Atkinson at @specterops.io framed my misgivings as a missing dimension and it just clicked. So I explored the concept of Execution Modality - www.elastic.co/security-lab...
Misbehaving Modalities: Detecting Tools, Not Techniques — Elastic Security Labs
We explore the concept of Execution Modality and how modality-focused detections can complement behaviour-focused ones.
elastic.co
One of the least discussed topics in detection engineering is maintenance. But why is no one talking about this? In this first blog we explore its relevance to #detectionengineering and the paradox that keeps us awake at night. Enjoy! falconforce.nl/why-is-no-on...
I just uploaded slides from an old talk on Windows x64 Stack Walking. github.com/jdu2600/conf...
github.com
💯 "Just because we can write a detection for something, doesn’t mean we should." infosecwriteups.com/what-makes-a...
What Makes a “Good” Detection?
Whether you’re a seasoned Detection Engineer or just starting to build out your SIEM, there comes a point where you need to ask yourself…
infosecwriteups.com
I wrote about how magic links (emailed one-time login links) frustrate me while explaining that they radically accept some fundamental truths. I argue that websites should layer passkeys on top of magic links to provide a seamless authentication experience for everyone. rmondello.com/2025/01/02/m...
Ricky Mondello » Magic Links Have Rough Edges, but Passkeys Can Smooth Them Over
rmondello.com