ShadowStrikePhantom
Research

Technical deep dives.

Kernel internals, detection engineering, and Windows security research from the ShadowStrike team. Every post is backed by real code in the Phantom repository.

FeaturedKernelProcess InjectionDetectionEngineering

How PhantomSensor Detects Process Injection in the Kernel

A deep walkthrough of how we intercept process injection attempts at kernel level — from WriteProcessMemory detection via handle callbacks to VAD tree manipulation tracking with VadTracker.

February 24, 2026
12 min read
Read article

Got a detection research topic you'd like to see covered? Open a discussion on GitHub or reach us at contact@shadowstrike.dev