ERNW is an independent IT Security service provider based in Heidelberg, Germany. Since its founding in 2001, our focus has been on consulting and testing in all areas of IT security, unallied from outside shareholders and a need to sell products. This independence and self-accountability drives us, as a company, to adhere to a higher standard of professional conduct and development.
Get the latest Informations about technical topics within the IT-Security Community and a lot of special insights. Sign up now for our Whitepaper Newsletter:
Thank you for signing up! You’ll receive a notification from out mailinglist manager to finally opt you in.
Process Hollowing is a technique used by various malware families (such as FormBook, TrickBot and Agent Tesla) to hide their malicious code within a benign appearing process. The typical workflow for setting up such a hollowed process is as follows: Create a new process (victim) using a benign executable, in suspended state. Unmap the executable […]