The internal architecture of Windows and Active Directory is examined, detailing the trust relationships of domains and forests, the features of Read-only Domain Controllers, vulnerabilities of group policies, and principles of privilege management. It discusses working with Kerberos, injection and...
dumping, tickets, hijacking user sessions, using WinAPI, COM, and Named Pipes in pentesting, as well as accessing native code from C#. Methods for bypassing information protection measures are described, including unhooking ntdll.dll, preventing DLL injection, loopholes for executing third-party code, utilizing hardware breakpoints, bypassing AMSI, and writing runners for shellcode on .NET. Practical recommendations for obfuscating WinAPI calls and protecting corporate networks from attacks are provided.
The internal architecture of Windows and Active Directory is examined, detailing the trust relationships of domains and forests, the features of Read-only Domain Controllers, vulnerabilities of group policies, and principles of privilege management. It discusses working with Kerberos, injection and dumping, tickets, hijacking user sessions, using WinAPI, COM, and Named Pipes in pentesting, as well as accessing native code from C#. Methods for bypassing information protection measures are described, including unhooking ntdll.dll, preventing DLL injection, loopholes for executing third-party code, utilizing hardware breakpoints, bypassing AMSI, and writing runners for shellcode on .NET. Practical recommendations for obfuscating WinAPI calls and protecting corporate networks from attacks are provided.
Be the first to know about our current discounts, offers and new products!
Check icon
You have added to your basket
Check icon
You have added to favourites
Sold out
The item is currently out of stock.
In stock
Available in warehouse. You will receive the exact delivery date from the operator after the order confirmation.
To order
The product is delivered directly from the publisher. The order processing time is up to 14 days, you will receive the exact delivery date from the operator after the order confirmation.
No circulation
Unfortunately, the print run of the book has ended, it is currently unavailable for order.