Detecting (un)Intentionally Hidden Injected Code By Examining Page Table Entries

6u6YBk7o_7Q/default.jpg

In this talk, we will cover hiding techniques that prevent executable pages (containing injected code) from being reported by current memory forensic plugins. These techniques can either be implemented by malware in order to hide its injected code (as already observed) or can, in one case, unintentionally be taken care of by the operating system through its paging mechanism.

By Frank Block

Full Abstract & Presentation Materials: https://www.blackhat.com/eu-19/briefi...

6u6YBk7o_7Q/default.jpg
Detecting (un)Intentionally Hidden Injected Code By Examining Page Table Entries Detecting (un)Intentionally Hidden Injected Code By Examining Page Table Entries Reviewed by Anonymous on March 18, 2020 Rating: 5