未公開のカーネルデータ構造を使ったホットキー型キーロガーの検知
ID: 71d1b5f9-86be-55be-970f-e9b112809add
STIX ID: report--71d1b5f9-86be-55be-970f-e9b112809add
Feed Name: Elastic Security Labs
This research article describes "hotkey" style keyloggers (demonstrated by the Hotkeyz PoC) which register many global hotkeys via RegisterHotKey to covertly capture keystrokes; it shows that ETW does not trace RegisterHotKey and proposes a kernel-mode detection method that locates and scans the undocumented gphkHashTable in win32kfull.sys to enumerate registered HOT_KEY objects, using a heuristic (count of registered alphanumeric keys) to detect keylogger activity; the author provides an implementation, GitHub repo, and a demo video.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
