Archive

16.05.2018 - 13:57 [ blackhat.com ]

Lost in Transaction: Process Doppelgänging

(4-7.12.2017)
• Advanced Code Injections Overview
• GhostWriting
• AtomBombing
• PowerLoader + PowerLoaderEx
• PROPagate
•…
• Reflective Loading
• Process Hollowing
• Injection method from over 10 years ago
• Has never received much attention

(…)

• Brief history of evasion techniques
• AV scanners
• Transacted NTFS (TxF)
• Evolution of Windows process loader

16.05.2018 - 13:18 [ enSilo.com ]

Microsoft’s Response to AtomBombing is Post-Infection Detection

(21.7.2017) The Microsoft update that addresses both “Process Hollowing” and “AtomBombing” will only be available for those that have purchased Windows Defender and will only be available in October or November 2017. Windows Defender ATP has only been addressing security issues for less than a year and Windows customers have to purchase Windows Defender ATP.