>_0xFORUM
Sign in

Detecting process hollowing from ETW (patched techniques)

in Defense39 replies2.6k views

Public, well-documented technique. This is about the detection side, not a how-to.

Signals that still hold: image name vs mapped path mismatch, StartAddress outside the primary image, protection flips on the image backing shortly after CreateProcess.

  • Image name vs mapped path
  • StartAddress outside primary
  • Protection flips after create

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 39 REPLIES

@blk

Please keep the hashes and drop the mystery zips. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-do

This matches a public n-day class from last patch Tuesday. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Full disk is a detection gap. Rate-limit logs, alert at 70%. I reproduced it on lab build 1144.

I dumped after OEP and then did this. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. 3am isolation notes must fit on a page. Version in my shot: current lab snapshot, not last year's blog.

Quietly the best note on this board this month. You wrote «Public, well-documented technique». That is the sentence I keep. Snapshot or it did not happen. I will not restore your VM again. Which build of the tool? I got burned mixing notes across versions. I reproduced it on lab build 1079.

@emmyfresh

This is the writeup I wanted when I was stuck. You wrote «Public, well-documented technique». That is the sentence I keep. Except the instan

Decompiler output is a hypothesis. Treat it like one. I reproduced it twice before I believed you. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. Allow-list entries expire. 90 days or they are a vulnerability. I wrote a 12-line script and then threw it away. The listing was enough.

@babatunde_k

Quietly the best note on this board this month. You wrote «Public, well-documented technique». That is the sentence I keep. Snapshot or it d

Calling the sticky 'priest talk' is how you earn a ban note. Please keep the hashes and drop the mystery zips. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. Jump box is not a desktop. No browser, no mail, no Slack. Took me 2 hours the first time.

I failed this exact class in January. You wrote «Public, well-documented technique». That is the sentence I keep. If debug requires turning the control off, the debug story is wrong. Version in my shot: current lab snapshot, not last year's blog.

Also: Allow-list entries expire. 90 days or they are a vulnerability.

I tried the naive path first and wasted a morning. You wrote «Public, well-documented technique». That is the sentence I keep. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. I still have the snapshot named defe-172-pre.

@danprodigy

I dumped after OEP and then did this. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented tec

You keep moving the goalposts. First it was the decoder, now it is the dump. This is the kind of thread that should be a sticky and is not. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. Full disk is a detection gap. Rate-limit logs, alert at 70%. Same class as the June thread, different binary.

@rr_or_gtfo

I tried the naive path first and wasted a morning. You wrote «Public, well-documented technique». That is the sentence I keep. Host-only NIC

Stop flexing an IDA license. The question was the unwind info. Quietly the best note on this board this month. The load-bearing line: Public, well-documented technique. If debug requires turning the control off, the debug story is wrong. My note id for this: ac-07.

@freshmode

I dumped after OEP and then did this. You wrote «Public, well-documented technique». That is the sentence I keep. Host-only NIC, no shared f

This is getting personal and it does not need to. I dumped after OEP and then did this. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. Full disk is a detection gap. Rate-limit logs, alert at 70%. I reproduced it on lab build 1108.

@build

This matches a public n-day class from last patch Tuesday. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-docu

That is a vibe. I asked for a listing offset. Same wall I hit last quarter. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Full disk is a detection gap. Rate-limit logs, alert at 70%. I wrote a 12-line script and then threw it away. The listing was enough.

I still keep a paper notebook for this kind of note. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. Full disk is a detection gap. Rate-limit logs, alert at 70%. I still have the snapshot named defe-172-pre.

@labsec

I still keep a paper notebook for this kind of note. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well

The graph hid it. The listing did not. Trust the listing. This belongs in the first-hour ritual. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Jump box is not a desktop. No browser, no mail, no Slack. I will +rep a listing and −rep a vibe. That is the deal.

@cloudx

This is the writeup I wanted when I was stuck. You wrote «Public, well-documented technique». That is the sentence I keep. Isolate the host

If you cannot paste bytes, you do not have a counterexample. I ran this on a licensed corpus binary. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. Snapshot or it did not happen. I will not restore your VM again. Is the hang the incomplete patch, or a second bug? I wrote a 12-line script and then threw it away. The listing was enough.

This is the writeup I wanted when I was stuck. You wrote «Public, well-documented technique». That is the sentence I keep. Isolate the host too, or stop calling the guest isolated. Took me 8 hours the first time.

Also: Jump box is not a desktop. No browser, no mail, no Slack.

I disagree with the tone, not the bytes. The load-bearing line: Public, well-documented technique. If debug requires turning the control off, the debug story is wrong. Pinned a comment at 0x140006912 in the listing.

I dumped after OEP and then did this. You wrote «Public, well-documented technique». That is the sentence I keep. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. Is the hang the incomplete patch, or a second bug? Pinned a comment at 0x140000732 in the listing.

@dfir

This is the kind of thread that should be a sticky and is not. «Detecting process hollowing from ETW (patched techniques)» — specifically Pu

This is the writeup I wanted when I was stuck. You wrote «Public, well-documented technique». That is the sentence I keep. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Version in my shot: current lab snapshot, not last year's blog.

@heapx

I failed this exact class in January. You wrote «Public, well-documented technique». That is the sentence I keep. If debug requires turning

That insult was not a technical point. I am reporting it. I reproduced it twice before I believed you. The load-bearing line: Public, well-documented technique. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. I wrote a 12-line script and then threw it away. The listing was enough.

@ibrahimvibe

I reproduced it twice before I believed you. The load-bearing line: Public, well-documented technique. Host-only NIC, no shared folders, no

Agreed on the class, not on the tool. The load-bearing line: Public, well-documented technique. Full disk is a detection gap. Rate-limit logs, alert at 70%. I wrote a 12-line script and then threw it away. The listing was enough.

@ismailtrend

Agreed on the class, not on the tool. The load-bearing line: Public, well-documented technique. Full disk is a detection gap. Rate-limit log

I am reporting the sample-drop hint. Hash and corpus tag only. If you only have the decompiler, you do not have the bug. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. Firewall rules not in the repo are unreviewed code. Hash of the public file, or are we arguing a shape? My note id for this: ac-23.

@meshx

I disagree with the tone, not the bytes. The load-bearing line: Public, well-documented technique. If debug requires turning the control off

Stop flexing an IDA license. The question was the unwind info. Bookmarking this for the lab wiki. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Isolate the host too, or stop calling the guest isolated. I will +rep a listing and −rep a vibe. That is the deal.

@nexor

Bookmarking this for the lab wiki. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Isolat

I still keep a paper notebook for this kind of note. You wrote «Public, well-documented technique». That is the sentence I keep. Snapshot or it did not happen. I will not restore your VM again. Can you quote the offset instead of the graph screenshot? I still have the snapshot named defe-172-pre.

@olamidee

I still keep a paper notebook for this kind of note. You wrote «Public, well-documented technique». That is the sentence I keep. Snapshot or

Calling the sticky 'priest talk' is how you earn a ban note. I dumped after OEP and then did this. You wrote «Public, well-documented technique». That is the sentence I keep. If debug requires turning the control off, the debug story is wrong. Pinned a comment at 0x14000497d in the listing.

I will argue the opposite and then probably agree. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Allow-list entries expire. 90 days or they are a vulnerability. My note id for this: ac-30.

@pwned

I will argue the opposite and then probably agree. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented t

That is a vibe. I asked for a listing offset. Bookmarking this for the lab wiki. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Firewall rules not in the repo are unreviewed code. Same class as the January thread, different binary.

Bookmarking this for the lab wiki. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. If debug requires turning the control off, the debug story is wrong. Version in my shot: current lab snapshot, not last year's blog.

Not fully convinced yet. The load-bearing line: Public, well-documented technique. Firewall rules not in the repo are unreviewed code. Same class as the June thread, different binary.

@secmod

Bookmarking this for the lab wiki. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. If deb

If you cannot paste bytes, you do not have a counterexample. If you only have the decompiler, you do not have the bug. The load-bearing line: Public, well-documented technique. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. What did you key the join on — PID or process GUID? My note id for this: ac-33.

@smartken

Not fully convinced yet. The load-bearing line: Public, well-documented technique. Firewall rules not in the repo are unreviewed code. Same

That insult was not a technical point. I am reporting it. I reproduced it twice before I believed you. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. I reproduced it on lab build 1363.

@sn0op

If you only have the decompiler, you do not have the bug. The load-bearing line: Public, well-documented technique. Except the instance, kee

I reproduced it twice before I believed you. The load-bearing line: Public, well-documented technique. Full disk is a detection gap. Rate-limit logs, alert at 70%. If anyone DMs me a zip I will not open it. Hash in-thread.

I would have written the opposite conclusion a year ago. The load-bearing line: Public, well-documented technique. Jump box is not a desktop. No browser, no mail, no Slack. Took me 10 hours the first time.

@stagx

I reproduced it twice before I believed you. The load-bearing line: Public, well-documented technique. Full disk is a detection gap. Rate-li

You keep moving the goalposts. First it was the decoder, now it is the dump. I reproduced it twice before I believed you. The load-bearing line: Public, well-documented technique. 3am isolation notes must fit on a page. I will +rep a listing and −rep a vibe. That is the deal.

@threx

I would have written the opposite conclusion a year ago. The load-bearing line: Public, well-documented technique. Jump box is not a desktop

I am reporting the sample-drop hint. Hash and corpus tag only. This matches a public n-day class from last patch Tuesday. The load-bearing line: Public, well-documented technique. Firewall rules not in the repo are unreviewed code. Was this on the licensed corpus or a crackme you wrote? My note id for this: ac-03.

This belongs in the first-hour ritual. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I still have the snapshot named defe-172-pre.

Also: 3am isolation notes must fit on a page.

@victor_lee

This matches a public n-day class from last patch Tuesday. The load-bearing line: Public, well-documented technique. Firewall rules not in t

I still keep a paper notebook for this kind of note. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. Isolate the host too, or stop calling the guest isolated. I wrote a 12-line script and then threw it away. The listing was enough.

@virt

This belongs in the first-hour ritual. On «Detecting process hollowing from ETW (patched techniques)»: Public, well-documented technique. Ex

Decompiler output is a hypothesis. Treat it like one. I will argue the opposite and then probably agree. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well-documented technique. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. My note id for this: ac-37.

@white

I still keep a paper notebook for this kind of note. «Detecting process hollowing from ETW (patched techniques)» — specifically Public, well

The graph hid it. The listing did not. Trust the listing. Did this on ARM64 last week — same shape, different pain. You wrote «Public, well-documented technique». That is the sentence I keep. 3am isolation notes must fit on a page. Pinned a comment at 0x1400024f5 in the listing.

This is the writeup I wanted when I was stuck. The load-bearing line: Public, well-documented technique. Snapshot or it did not happen. I will not restore your VM again. After you did that, did the decompiler pick it up or did you dump? My note id for this: ac-38.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.