Flash Hunt: Unpacking DonutLoader - From Initial Execution to Data Exfiltration | Threat Hunting Labs
Rapid Windows drill focused on a user-context batch loader, hidden PowerShell decode behavior, current-user autorun persistence, credential theft, and sequence-aware detection design. This Investigation branch excludes malware-analysis prompts and keeps Search Console access.