1 Jul 2024, 14:11 UTC≈4,910 views27 reactionsread 8 August 2026 Photo
Dumping LSASS against CrowdStrike: We frequently receive feedback from our users highlighting their success in engagements and how Maldev Academy contributed. Today, we received a message detailing their effective use of New Modules 23, 25, and 38 to successfully bypass CrowdStrike and dumping LSASS.
❤21👍4👏2
13 Jun 2024, 08:48 UTC≈5,060 views12 reactionsread 8 August 2026 Photo
Learn about Event Tracing for Windows (ETW) and the different bypass techniques.
❤8👍4
11 Jun 2024, 10:44 UTC≈4,310 views6 reactionsread 8 August 2026 Photo
DLL sideloading has been covered in several modules. We recommend users that have completed these modules to try the DLL sideloading challenge.
❤3👍3
21 Apr 2024, 09:12 UTC≈4,380 views13 reactionsread 8 August 2026 We've updated our code snippets database. This update includes Python Impacket & C/C++ snippets. Copy, paste and use.
https://search.maldevacademy.com/updates
Some of the snippets include:
- Enumerate Remote Host
- SMB Pass-The-Hash
- Share Enumeration
- List SMB Files
- Download/Upload Via SMB
- Query SMB Share Permissions
- Query Remote Service
- Start Remote Registry
- Create Remote Service
- Extract WiFi Passwor…
❤13
10 Apr 2024, 11:17 UTC≈3,890 views9 reactionsread 8 August 2026 Our next update will demonstrate how we can make EDRs behave unexpectedly against certain files names and attributes.
The update will provide information that can allow further vulnerability research against security solutions.
❤7😍2
3 Apr 2024, 17:39 UTC≈3,620 views8 reactionsread 8 August 2026 Update 9 has been finalized and QA’d.
Modules:
[1] Ghost Process Injection
[2] Ghostly Hollowing
[3] Herpaderping Process Injection
[4] Herpaderply Hollowing
[5] Shellcode Reflective DLL Injection
Challenges:
[1] Remote Module Stomping
[2] Process Hollowing
[3] PSExec Implementation
The next update will include the following modules:
[1] Patchless Threadless Injection Via Hardware Breakpoints
[2] Tampered Syscal…
❤6👍2
19 Mar 2024, 13:41 UTC≈3,140 views14 reactionsread 8 August 2026 Photo
Shellcode Reflective DLL Injection (sRDI) Module ✅
Herpaderply Hollowing Module✅
Ghostly Hollowing Module✅
🔥14
16 Mar 2024, 09:14 UTC≈3,110 views13 reactionsread 8 August 2026 In update 1 we released our first "Exploiting EDRs For Evasion" module. We're planning to showcase more weaknesses with the following modules:
1. Exploiting EDRs For Evasion - Preventing EDR From Taking Action
2. Exploiting EDRs For Evasion - Finding Internal Exclusions
3. Exploiting EDRs For Evasion - EDR LOLBINs
4. Exploiting EDRs For Evasion - Weak File Permissions
🔥8❤4👍1
21 Feb 2024, 20:00 UTC≈5,790 views12 reactionsread 8 August 2026 We’ve launched Maldev Academy Code Search!
http://search.maldevacademy.com
We’ve built two projects with the help of this service and posted the code and videos to the GitHub repository below:
https://t.co/Xbgell6Ykl
❤8😱4
13 Feb 2024, 14:01 UTC≈3,250 views10 reactionsread 8 August 2026 Photo
The upcoming Maldev Academy update will showcase a module that explains the process of developing a 'Shellcode Reflective DLL' builder.
This builder converts your DLL payload into position-independent shellcode, allowing you to load any DLL reflectively.
❤5🔥3🆒2
5 Feb 2024, 22:44 UTC≈2,910 views15 reactionsread 8 August 2026 Photo
Maldev Academy Code Search:
We’re very happy to announce the creation of a new code search service that will ease the learning and maldev experience for users.
The site currently has over 7000+ lines, 300+ snippets in total with new snippets being added every month.
All snippets were rewritten from scratch and are modular. Not all snippets overlap with the Maldev Academy course.
Snippets reference Maldev Academy …
❤15
26 Jan 2024, 17:39 UTC≈3,130 views8 reactionsread 8 August 2026 We’re continuing to publish working code on our GitHub. We’ll be publishing a new repository next week.
Follow us to stay tuned.
https://github.com/Maldev-Academy
❤8
Showing the 12 most recent of 17 posts we hold for @maldevacademy. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.