NNMNoman Nasir MinhasCybersecurity researcher & developer
  • Profile
  • Work
    • Projects
    • Research
    • Skills
  • Blogs
    • Featured Posts
    • All Posts
  • PenTesting Guide
  • Contact
allmalware-analysis1windows-internals1kernel1security-research1dynamic-analysis1ssdt1rootkit1reverse-engineering1

Nanga: Process Telemetry from the Syscall Layer

May 26, 202615 min read

A kernel-driver approach to malware dynamic analysis that captures process telemetry below user-mode evasion, at the syscall layer.

malware-analysiswindows-internalskernelsecurity-researchdynamic-analysisssdtrootkitreverse-engineering
user@nnm:~$ © 2026 Noman Nasir Minhas. @sheldon