Revisiting Ring3 API Hooks: Tricks to Defeat Analysis Tools - Rafael Salema Marquez - Ekoparty - 2021
Ekoparty Security Conference via YouTube
Overview
Syllabus
Introduction
Agenda
Rafaels background
What is important
Dark side
Credentials
Expose new techniques
Basic knowledge
What is API hooks
Avoid distractions
Inline hooks
IAT hooks
Regular flow
How it works
Detection strategies
Egg hook
Egg hook explanation
Create process suspended
allocate memory
the fun part
proof of concept
virtual machine
fast look
results
actual results
outro
Taught by
Ekoparty Security Conference