It is a false assumption that ransomware will use the Windows Crypto API. Ransomware may implement their own cryptography routines instead of using the provided APIs as they may be monitored for abuse.
false assumption: ransomware will use Crypto API
2026-09-10
Recent Posts
Linux Persistence: Modular Software
2025-04-17 DFIR CTF persistence linux persistence apache asterisk
Linux Persistence: Web Shells
2025-04-16 DFIR persistence webshell linux persistence webshell apache nginx PHP
Linux Persistence: Rootkits
2025-04-15 DFIR persistence rootkit LKM linux persistence LKM rootkit LD_PRELOAD kprobe ftrace ld.so hooking