Valhguard logo

Blog

Forged By Attackers, Built For Defenders

Latest Insights

Article banner for In-Memory .NET: red-team execute-assembly with no disk on the left, blue-team CLR ETW, AMSI and out-of-process detection on the right
In-Memory .NET: Where the CLR’s Telemetry Actually Lives

Patch ETW and the CLR goes dark, load from a byte array and you dodge AMSI, Sysmon catches the DLL load anyway. Two of those are wrong on modern .NET and the third is structurally impossible. Where the telemetry for in-memory .NET really is, and which signals survive an operator inside the process.

Read More »
Article banner for Virtualization as a Weapon: detecting portable QEMU
Virtualization as a Weapon: Detecting Portable QEMU and Red Team VMs

Virtualization is not just infrastructure; it is a weapon. Red Teams leverage portable QEMU instances to bypass host-based EDRs and evade behavioral analysis. We analyze how attackers deploy these “invisible machines” without administrative privileges and provide the KQL hunting queries defenders need to detect unauthorized virtualization on their networks.

Read More »