3 ms·
I thought with x64 the days of AV hooking up random places of the kernel were over?
by pedro2 4y ago
I thought with x64 the days of AV hooking up random places of the kernel were over?
- therein 4y agoThey aren't. AV and AC software continue hooking system functions to this day. PatchGuard doesn't cover every .data ptr and procedure. You can do things with IoAllocateMdl, MmProbeAndLockProcessPages, MmMapLockedPagesSpecifyCache, MmProtectMdlSystemAddress to achieve such tasks. They don't even need to be public, you can just walk the exports of ntoskrnl.exe etc. You can even do insane shit like changing the PML4 of a process to the PML4 of another and have them point to the same memory. Or change the Win32Thread of your KTHREAD structure to that of explorer.exe and draw on the screen from kernel with GDI commands.