Certulitis – one tool that keeps on giving

August 30, 2020 in Archaeology, Undocumented Windows Internals

Update EC who is one of the most technical guys I know pinged me because he figured out the meaning of that 0x00FB switch, The idea behind it is Windows […]

Sleeping DLL beauties

February 4, 2020 in Random ideas, Silly, Undocumented Windows Internals

How do we sleep? We do one of these: kernel32/kernelbase ! Sleep kernel32/kernelbase ! SleepEx ntdll ! ZwDelayExecution but… not only. Windows 10 offers more libs with more sleeping goodness: […]