Low-Level Maestro Series 2026

10 masterclasses avancées pour plonger dans le cœur du système : firmware, kernel, hyperviseur, eBPF, mémoire furtive… Pour les cyberdéfenseurs qui veulent comprendre les attaques les plus pointues (et les contrer).

⚠️ Recherche & formation éthique uniquement – Lab air-gapped obligatoire – Toute utilisation malveillante est illégale (Art. 323-1 Code pénal)
01

Early Bird APC Injection

Pure x64 ASM – Exécution avant EntryPoint, timing evasion, syscall polymorphism.

02

Reflective DLL Injection

Manual PE mapping, relocations, imports hashing – sans LoadLibrary.

03

DKOM Process Hiding

Kernel driver x64 – Unlink EPROCESS, evasion KDP/HVCI.

04

Hell's Gate & Halo's Gate

Direct syscalls evasion – Résolution dynamique SSN, fallback intelligent.

05

Inline Hooking SSDT

Windows kernel – Hook NtOpenProcess pour cacher processus.

06

UEFI Bootkit Advanced

Persistence pré-OS, DXE injection, SPI flash, Secure Boot bypass.

07

Manual Map Shellcode Injection

Parsing PE pur ASM – Injection sans LoadLibrary.

08

eBPF Stealth Rootkit (Linux)

Hide process/network, bypass bpftool – Kernel 5.15+.

09

Process Ghosting & Herpaderping

File mapping evasion – Section manipulation 2026.

10

Hypervisor-based Process Hiding

Ring -1 avec VT-x – #VE handler, EPT stealth.

11

HADES CORE IA v2.0

Parse specs → encodeur ML optimisé (10k+ firmwares) → flux 0/1 polymorphique pour x86/ARM/RISC-V/SMM/TrustZone.