Post B6B36NZCmUModSiDeS by wfh@infosec.exchange
(DIR) More posts by wfh@infosec.exchange
(DIR) Post #B64toynpXFduN8QDhI by malwaretech@infosec.exchange
0 likes, 0 repeats
@wfh Nice work dude! I assume this locks down the ABE bypasses that work via injecting into the broker and hijacking the COM session? Does it also apply to Chrome processes launched via CreateProcess suspended for process hollowing purposes?
(DIR) Post #B6B36NZCmUModSiDeS by wfh@infosec.exchange
0 likes, 0 repeats
@malwaretech yes it prevents that, and hollowing, and debugging. But the security properties are not yet fully hardened so right now I'm really looking for any feedback on App-Compat issues. Try it out!