Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Injecting Code into Windows Protected Processes using COM - Part 1

Summary

At Recon Montreal 2018 I presented “Unknown Known DLLs and other Code Integrity Trust Violations” with Alex Ionescu. We described the implementation of Microsoft Windows’ Code Integrity mechanisms and how Microsoft implemented Protected Processes (PP). As part of that I demonstrated various ways of bypassing Protected Process Light (PPL), some requiring administrator privileges, others not.
Published
Collected

original ↗