<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>jalster</title><description>Security writeups, notes and research by jalster.</description><link>https://jalster.org/</link><item><title>Dumping LSASS on a fully-patched Windows 11 with a 2014 .exe</title><link>https://jalster.org/posts/wsass/</link><guid isPermaLink="true">https://jalster.org/posts/wsass/</guid><description>No malware, no MiniDumpWriteDump. Just a signed WER binary from Windows 8.1 that Microsoft still trusts to write an unencrypted minidump of a PPL process.</description><pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate><category>red-team</category><category>windows-internals</category><category>credentials</category><category>defender</category></item><item><title>NTDLL stubs, SSNs and where EDRs really watch</title><link>https://jalster.org/posts/ntdll-hooks-syscalls/</link><guid isPermaLink="true">https://jalster.org/posts/ntdll-hooks-syscalls/</guid><description>The difference between an EDR seeing an attack or missing it is often 5 bytes in memory. A walkthrough of user-land hooks, the classic bypasses, and why kernel callbacks make them insufficient today.</description><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><category>edr</category><category>windows-internals</category><category>red-team</category><category>blue-team</category></item></channel></rss>