BlahCats Blog

Tales of a binary encoded life...

Tapping into the potential of Memory Dump Emulation

Published by hugsy , on 27 January 2024 , under research

This post summarizes some of the work I’ve been doing for the past few months during my (few) off times. Nothing new, mostly just a structured reminder for my later self. Introduction What-The-Fuzz is…

Section Objects as Kernel/User communication mode

Published by hugsy , on 4 April 2023 , under research

I’ve recently decided to read cover to cover some Windows Internals books, and currently reading the amazing book “What Makes It Page”, it gave me some ideas to play with Section Objects as they cover…

Install Hyper-V & Sandbox on Windows 10/11 Home

Published by hugsy , on 6 August 2022 , under minis

Another lie, probably put in place from MS marketing team to force the hand and make more people purchase Windows 10/11 Professional licenses: Hyper-V and Windows Sandbox can be installed on Windows 1…

WinDbgX undocumented workspace options

Published by hugsy , on 17 July 2022 , under minis

How to use WinDbgX workspaces to make debugging even easier. Workspaces WinDbgX workspaces (suffixed .debugTargets) are nothing more than XML files that instructs WinDbgX how to process with the curre…

Setup KDCOM for 2 Hyper-V VMs

Published by hugsy , on 14 July 2022 , under minis

How to use Hyper-V to debug using KdCOM from 2 VMs, one debugging the other. Debuggee Follow the setup here to setup a BCD profile for KdCom in the VM. Shutdown the VM and in a privileged prompt on th…