Object Overloading: A Novel Approach to Sneaking…
ID: 76cad3a6-e6f7-5329-94bb-f53c5a530b63
STIX ID: report--76cad3a6-e6f7-5329-94bb-f53c5a530b63
Feed Name: TrustedSec blog
This post demonstrates an offensive proof-of-concept called “Object Overloading” that abuses the Windows Object Manager and per-process DosDevices (ProcessDeviceMap) to override a process's view of the C: drive, enabling DLL hijacking/loading of attacker-controlled DLLs (including from network shares). The author provides detailed background on Object Manager symbolic links, sample C/C++ and DLL code to create per-process device maps and to patch process entrypoints to keep the target stable, discusses limitations (DLL must exist on disk, KnownDLLs interactions, detection caveats), and links to prior research and videos.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
