首页
社区
课程
招聘
[转帖]PROCESS HERPADERPING – WINDOWS DEFENDER EVASION
发表于: 2021-1-19 05:31 2484

[转帖]PROCESS HERPADERPING – WINDOWS DEFENDER EVASION

2021-1-19 05:31
2484

PROCESS HERPADERPING – WINDOWS DEFENDER EVASION

Windows Defender has improved significantly the security posture of Windows environments since it has better detection capabilities compare to other security products. When a process is created Windows Defender receives a notification since it has a register callback on the kernel. However the actual inspection of the file occurs when the thread is inserted and before the process initiates on the system and not when the process object is created.


Johnny Shaw released publicly a technique called Process Herpaderping which could be used to evade security products including Windows Defender. The evasion works because the contents of the file that created the process object on the system are modified before the insertion of the thread. Therefore when the process initiates Windows Defender cannot determine if should allow execution or flag the process as malicious since the initial binary which started the process doesn’t match to what is actually executed.

926K9s2c8@1M7s2y4Q4x3@1q4Q4x3V1k6Q4x3V1k6H3k6h3&6@1k6i4y4@1L8r3q4T1L8%4u0S2N6r3!0J5K9h3g2K6i4K6u0W2j5$3!0E0i4K6u0r3x3U0l9J5x3g2)9J5c8U0l9I4i4K6u0r3x3e0S2Q4x3V1k6H3M7X3!0U0k6i4y4K6i4K6u0V1K9r3g2J5M7r3q4V1k6i4u0H3K9h3&6Y4i4K6u0V1N6$3W2F1k6r3!0%4M7#2)9J5k6r3c8W2k6X3g2F1k6r3g2J5i4K6u0V1k6i4k6S2M7$3W2G2L8W2)9J5c8R3`.`.



[培训]科锐软件逆向54期预科班、正式班开始火爆招生报名啦!!!

收藏
免费 1
支持
分享
最新回复 (2)
雪    币: 2453
活跃值: (9040)
能力值: ( LV2,RANK:15 )
在线值:
发帖
回帖
粉丝
2

网页本地存档

上传的附件:
2021-1-19 06:12
0
雪    币: 111951
活跃值: (203399)
能力值: (RANK:10 )
在线值:
发帖
回帖
粉丝
3
FleTime 网页本地存档
2021-1-19 06:15
0
游客
登录 | 注册 方可回帖
返回