Avoiding Memory Scanners
ID: 18cac8b4-18c9-523d-b42b-1c09cbfd8485
STIX ID: report--18cac8b4-18c9-523d-b42b-1c09cbfd8485
Feed Name: Black Hills Infosec Blog
This research/post describes methods to evade Windows memory scanners and endpoint detection by obfuscating and encrypting in-memory implants. It documents techniques including multi-byte/RC4 encryption via SystemFunction032, secondary-heap encryption, executable masking stubs, ROP and NtContinue-based FOLIAGE context switching, replacing Sleep with WaitForSingleObject, and return-address spoofing, and it introduces AceLdr — an open-source reflective loader implementing these techniques to bypass scanners like YARA, PE-sieve, Moneta, and BeaconHunter.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
