Royce Yaezenko, 0xtengu, assistant researcher
Malware analysis often focuses on detonation, leaving new defenders and red‑teamers wondering how a loader is actually assembled. In this accelerated, beginner‑friendly, two‑hour hands‑on workshop, participants start with a ready‑to‑build Visual Studio solution and finish with a fully functional Windows 11 process‑injection loader written in C. We focus on the classic three‑call technique: VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread, plus a quick single‑byte XOR obfuscation pass and file bloating operation. All workshop time is devoted to getting a working loader, testing it against Windows Defender, and understanding each step well enough to particpants can expand beyond it.
___________________________________________________________
The Red Team Village
Red Team Village Website: redteamvillage.io
Discord: redteamvillage.io/discord
Twitter: twitter.com/RedTeamVillage_
Instagram: instagram.com/theredteamvillage
BlueSky: bsky.app/profile/theredteamvillage.bsky.social