This is the link to my x33fcon 2025 Talk this year: Taming the Windows Loader for Stealthy Injection
The Github page associated to that technique contains some technical data illustrating what I am talking about, and the slides are available at this link