logo

How Attackers Hide Processes by Abusing Kernel Patch Protection

ID: fe4af57f-4e56-5f19-9fdd-45cdcfe28fb6

STIX ID: report--fe4af57f-4e56-5f19-9fdd-45cdcfe28fb6

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-01-08

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

**Executive summary:** Security researchers describe a timing-based Windows kernel technique that hides malicious processes from Task Manager and monitoring tools by using the documented PsSetCreateProcessNotifyRoutineEx callback to repair ActiveProcessLinks just before PspProcessDelete integrity checks run, effectively bypassing PatchGuard and HVCI; the research warns of significant detection and persistence implications but notes practical deployment requires kernel-mode execution and signed or compromised drivers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.