<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Alexander Golovin on Purpleshift</title><link>https://purpleshift.io/authors/alexander-golovin/</link><description>Recent content in Alexander Golovin on Purpleshift</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026</copyright><lastBuildDate>Mon, 06 Apr 2026 07:12:39 +0000</lastBuildDate><atom:link href="https://purpleshift.io/authors/alexander-golovin/index.xml" rel="self" type="application/rss+xml"/><item><title>Invisible attacks with bind mount</title><link>https://purpleshift.io/purple/2026-04-06-oqqa/</link><pubDate>Mon, 06 Apr 2026 07:12:39 +0000</pubDate><guid>https://purpleshift.io/purple/2026-04-06-oqqa/</guid><description>A technique much simpler than rootkit can make a malicious process invisible</description></item><item><title>Disabling Windows Defender via symlink</title><link>https://purpleshift.io/purple/2026-01-12-bmka/</link><pubDate>Mon, 12 Jan 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-01-12-bmka/</guid><description>Built-in antivirus could be switched off without any third-party software</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/purple/2026-01-12-bmka/featured_Defender.png"/></item></channel></rss>