>_0xFORUM
Sign in

CFG / XFG as a hunting signal, not as a silver bullet

in Defense5 replies4.1k views

I hunt binaries that should have CFG and do not, on a path that should be signed. That is a drift hunt, not a exploit-stopper brag.

CFG is a compiler flag. Treat it like one.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 5 REPLIES

@zero

Agreed on the class, not on the tool. You wrote «I hunt binaries that should have CFG and do not, on a path that should be signed». That is

Calling the sticky 'priest talk' is how you earn a ban note. Did this on ARM64 last week — same shape, different pain. «CFG / XFG as a hunting signal, not as a silver bullet» — specifically I hunt binaries that should have CFG and do not, on a path that should be signed. Allow-list entries expire. 90 days or they are a vulnerability. My note id for this: af-02.

I would have written the opposite conclusion a year ago. The load-bearing line: I hunt binaries that should have CFG and do not, on a path that should be signed. Full disk is a detection gap. Rate-limit logs, alert at 70%. Was this on the licensed corpus or a crackme you wrote? I will +rep a listing and −rep a vibe. That is the deal.

@analytx

I would have written the opposite conclusion a year ago. The load-bearing line: I hunt binaries that should have CFG and do not, on a path t

This is the kind of thread that should be a sticky and is not. The load-bearing line: I hunt binaries that should have CFG and do not, on a path that should be signed. 3am isolation notes must fit on a page. Took me 2 hours the first time.

Did this on ARM64 last week — same shape, different pain. You wrote «I hunt binaries that should have CFG and do not, on a path that should be signed». That is the sentence I keep. Full disk is a detection gap. Rate-limit logs, alert at 70%. Pinned a comment at 0x140002379 in the listing.

@westsideguy

Did this on ARM64 last week — same shape, different pain. You wrote «I hunt binaries that should have CFG and do not, on a path that should

Agreed on the class, not on the tool. You wrote «I hunt binaries that should have CFG and do not, on a path that should be signed». That is the sentence I keep. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. Version in my shot: current lab snapshot, not last year's blog.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.