logo

未公開のカーネルデータ構造を使ったホットキー型キーロガーの検知

ID: 71d1b5f9-86be-55be-970f-e9b112809add

STIX ID: report--71d1b5f9-86be-55be-970f-e9b112809add

Feed Name: Elastic Security Labs

Threat Score
50/100

Date Published: 2025-03-04

Date Updated: 2026-04-27

...
...

This research article describes "hotkey" style keyloggers (demonstrated by the Hotkeyz PoC) which register many global hotkeys via RegisterHotKey to covertly capture keystrokes; it shows that ETW does not trace RegisterHotKey and proposes a kernel-mode detection method that locates and scans the undocumented gphkHashTable in win32kfull.sys to enumerate registered HOT_KEY objects, using a heuristic (count of registered alphanumeric keys) to detect keylogger activity; the author provides an implementation, GitHub repo, and a demo video.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.