JYenn

JYenn

Security researcher · Malware developer · Pentester
Bypassing Sophos Intercept X

Sophos Intercept X: A Technical Bypass

Why Zig I got bored again. So I started learning Zig syntax and how it could be beneficial when it comes to writing loaders. I just wanted something new to try, and with Zig being early days still I thought why not. There aren’t many variations out there currently, so in terms of signatures and pattern detection Zig plays a role here although the underlying behaviour is the same. If you’re new to Windows internals there are some amazing resources and tools out there to help, such as SysWhispers which handles all the syscalls and structs for you. But I was taught to use MSDN for the Win32 functions and NtDoc for the undocumented counterpart. I mention this because it forces you to understand how the structs work and the pointers to such. Both are a goldmine of info :). Also definitely head over to Crr0ww, I can’t recommend his videos enough for explaining these topics. Even better, the homies at Church of Malware are always helpful with anything, I can’t praise them enough, truly inspiring. ...

2026-07-22 · 15 min · JYenn