OW64 Windows Tradecraft — Detailed Notes
OW64 Windows Tradecraft — Detailed Notes
BLUF. This library contains attack-focused Windows, Active Directory, and EDR-evasion notes. Use only in an authorized lab or engagement. Platform mechanics remain in Platform Internals, while defensive validation lives in the Windows Domain Playbook.
Tracks
| Track | Start with | Contents |
|---|---|---|
| Active Directory | External initial access | Entry, credential access, domain enumeration, privilege escalation, persistence, trusts, lateral movement, protocols, and ports |
| EDR evasion | Resources → EDR red-team view | Binary transformation, delivery resistance, syscalls, API hooking, and EDR-focused theory |
| Windows attacks | Enumerate Windows | Windows enumeration, AMSI, and EDR attack notes |
| Case studies | WDAC/Loki C2 study | Vulnerability and public-article deep dives |
Parent pillars
Boundary
- The material here explains offensive techniques and adversary behavior.
- Detection, hardening, baseline, and evidence exercises belong in the Windows Domain Playbook.
- PE, syscall, loader, authentication, and memory fundamentals belong in Platform Internals.