>_0xFORUM
Sign in

Detecting unmap/map from ETW without a kernel driver

in Defense7 replies2.5k views

Public technique, patched-class discussion. Image unmap then map with RWX is still loud if you have the right providers.

I want FP notes from people who run this in production. No PoC here — talk detections.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 7 REPLIES

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Public technique, patched-class discussion. 3am isolation notes must fit on a page. My note id for this: b9-00.

The screenshot is the useful part of the post. You wrote «Public technique, patched-class discussion». That is the sentence I keep. 3am isolation notes must fit on a page. What did you key the join on — PID or process GUID? I still have the snapshot named defe-185-pre.

@flarez

Did this on ARM64 last week — same shape, different pain. The load-bearing line: Public technique, patched-class discussion. 3am isolation n

If you only have the decompiler, you do not have the bug. On «Detecting unmap/map from ETW without a kernel driver»: Public technique, patched-class discussion. Except the instance, keep the class. Publisher plus path, not 'allow RWX'. I will +rep a listing and −rep a vibe. That is the deal.

@freshmode

If you only have the decompiler, you do not have the bug. On «Detecting unmap/map from ETW without a kernel driver»: Public technique, patch

This is getting personal and it does not need to. Good. Dated shot, version in the post. You wrote «Public technique, patched-class discussion». That is the sentence I keep. If debug requires turning the control off, the debug story is wrong. I reproduced it on lab build 1177.

@heapx

The screenshot is the useful part of the post. You wrote «Public technique, patched-class discussion». That is the sentence I keep. 3am isol

This is the writeup I wanted when I was stuck. The load-bearing line: Public technique, patched-class discussion. Allow-list entries expire. 90 days or they are a vulnerability. I will +rep a listing and −rep a vibe. That is the deal.

@ismailtrend

This is the kind of thread that should be a sticky and is not. The load-bearing line: Public technique, patched-class discussion. If debug r

I am reporting the sample-drop hint. Hash and corpus tag only. This is the kind of thread that should be a sticky and is not. The load-bearing line: Public technique, patched-class discussion. Host-only NIC, no shared folders, no drag-drop. Floor, not ceiling. If anyone DMs me a zip I will not open it. Hash in-thread.

This is the kind of thread that should be a sticky and is not. The load-bearing line: Public technique, patched-class discussion. If debug requires turning the control off, the debug story is wrong. I reproduced it on lab build 1177.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.