General Lab Recommendations
  • Complete AD lab with 1 dedicated debug workstation. At least 1 Windows VM with WinDbg and Sysinternals.
  • MinGW toolchain installed on Linux or WSL.
  • Detection blogs require an Elastic SIEM server and at least 1 Elastic EDR agent.
  • Without SIEM: use Fibratus CLI, Dashboard HTML and pipeline.py.
JellyBee Internals PILL

Inside a swarm of shellcodes, this is PILL

Conceptual base of PILL inside a shellcode swarm: why it exists, what problem it solves, and where compiler details begin.