October 14, 2021 at 11:40PM

■■□□□ Malware can escape a debugging session by implementing TLS callbacks that will be executed before the entry point. Their addresses are pointed by the PE header’s data directory IMAGE_DIRECTORY_ENTRY_TLS.

https://t.me/cKure/9763