Month: September 2026
-

Dump Encoding Library
The Windows Error Reporting Dump Encoding Library (WerEnc.dll) is a Microsoft signed DLL that can be abused by threat actors to encrypt their implant using a trusted Microsoft cryptographic implementation. Threat actors can develop smaller stagers without using crypto code, enabling them to have improved evasion capabilities against endpoint detection…
-

Windows Security Center
The Windows Security Center collects and presents information about the status of the antivirus control (Windows Defender or 3rd party). When a third-party antivirus is installed, Windows Defender transitions to passive mode to avoid scanning collisions. Threat actors can abuse the Windows Security Center (WSC) API to disable Windows Defender…
