Every technical term in the course, defined in plain English. Click any term to jump to the module where it's used.
AMSI
WINDOWS // DEFENSE
Anti-Malware Scan Interface. A Windows security feature that scans scripts and commands before they run. If it sees something suspicious, it blocks it. Hackers bypass it to run malicious code undetected.
Example: PowerShell script downloads a file → AMSI scans it → detects malicious pattern → blocks execution. Bypass: intercept AMSI's scan function and always return "clean".
Event Tracing for Windows. Microsoft's logging system that records everything happening on a computer — process starts, network connections, file access. Security teams use it to detect attacks. Hackers disable it to hide their tracks.
Example: Malware starts → ETW logs "ProcessCreated: malware.exe" → SIEM alerts security team. Bypass: intercept ETW's write function and discard the log entry.
Small piece of code that does one thing: give the attacker control. It's not a full program — it's a payload, usually injected into another process. Named "shell" because it often opens a command shell (terminal) for the attacker.
Example: 300 bytes of machine code that opens a network connection to attacker IP, then executes every command sent over that connection. Injected into Notepad.exe so it looks legitimate.
Command and Control. The communication channel between an attacker and their malware. The attacker sends commands ("download this file", "take a screenshot") and the malware sends back results. C2 channels hide in normal traffic — DNS, HTTPS, cloud storage.
Example: Malware checks GitHub Gist every 5 minutes for encoded commands. Attacker edits the Gist → malware sees change → executes command. Looks like normal GitHub traffic to firewalls.
Going from a normal user to an administrator, or from administrator to SYSTEM. It's the difference between "can use the computer" and "can do anything to the computer." Most attacks start with normal access and escalate to total control.
Example: Employee clicks phishing link → malware runs as standard user → finds Windows bug → exploits bug → becomes SYSTEM → installs rootkit → invisible forever.
Malware that hides itself. Not just from the user — from the operating system, from antivirus, from forensic tools. It intercepts system calls and lies: "No, that process isn't running." "No, that file doesn't exist." The most dangerous malware because you can't find what you can't see.
Example: Rootkit hooks Windows API function "NtQuerySystemInformation" → when Task Manager asks "what processes are running?" → rootkit removes itself from the list → Task Manager shows everything except the rootkit.
Fake email or message designed to steal credentials, install malware, or trick the user into revealing information. The email looks legitimate — same logo, same sender name, same writing style. Only the link is fake.
Example: Email from "security@microsoft.com" says "Your account will be locked in 24 hours. Click here to verify." Link goes to attacker-controlled clone of Microsoft login page. User enters credentials → attacker has them.
Moving from one compromised computer to another. The attacker doesn't stop at the first machine — they use it as a stepping stone to reach other machines, especially servers and domain controllers. The goal: from one workstation to the entire network.
Example: Compromise HR workstation → find credentials in browser → use credentials to RDP to finance server → find database connection string → connect to SQL server → dump customer database → exfiltrate.
Simple encryption where every byte is flipped against a key. Not secure against real cryptanalysis, but enough to hide strings from antivirus signature matching. "malware.exe" XORed with 0x42 becomes "kco{wd.g" — no longer matches the signature.
Example: Shellcode contains string "http://evil.com/c2" → XOR with 0xBE → becomes unreadable garbage → antivirus can't match "evil.com" → at runtime, XOR again with 0xBE → original string restored → connection established.
Hardware Breakpoint. A CPU feature that stops execution when a specific memory address is accessed. Used for debugging. Hackers use it to intercept security functions — when AMSI tries to scan, the CPU triggers the breakpoint, the hacker's code runs first, and returns "clean" before AMSI can do its job.
Example: Set HWBP on AmsiScanBuffer function → Windows calls AmsiScanBuffer to check if script is malicious → CPU pauses, calls hacker's handler → handler returns S_OK (clean) → Windows thinks script is safe → executes it.