Sam Russell


Reversing complex jumptables in Binary Ninja

Jul 15, 20224 min read

I've recently started reversing some of the Tigress obfuscator challenges, and I decided to use this to test out some of the functionality in Binary...

Shellcode injection using ThreadNameInformation
Why NtSetContextThread destroys volatile registers
Extracting the SSDT directly from ntoskrnl.exe
NtSetInformationThread: Disabling ThreadHideFromDebugger