Moonlit observatory of research and tooling

MiscResearch

Windows security research for those who come after.

A growing archive of ETW notes, LOLBIN investigations, Windows internals, compatibility research, and supporting tooling.

    Moonlight / Dawn

    Two ways into the work, depending on what you need.

    Research collects findings, decoded behavior, and durable reference material. Tooling holds the scripts, proofs-of-concept, and smaller experiments that grew out of that work.

    Latest Transmission

    Check out the latest work.

    Moonlight guides the way.

    Latest Note

    2026-05-07

    Windows Process Internals - Fondue.EXE

    An in-depth look at Fondue.EXE, CLI options, the "rude app" checks, the handoff to APPWIZ.CPL and a bit of DLL side-loading.

    Process AnatomyResearchwindows-processes · windows
    Read latest note

    Recent Notes

    More recent writing from across the archive.