How Attackers Hide Processes by Abusing Kernel Patch Protection
ID: fe4af57f-4e56-5f19-9fdd-45cdcfe28fb6
STIX ID: report--fe4af57f-4e56-5f19-9fdd-45cdcfe28fb6
Feed Name: GBHackers
**Executive summary:** Security researchers describe a timing-based Windows kernel technique that hides malicious processes from Task Manager and monitoring tools by using the documented PsSetCreateProcessNotifyRoutineEx callback to repair ActiveProcessLinks just before PspProcessDelete integrity checks run, effectively bypassing PatchGuard and HVCI; the research warns of significant detection and persistence implications but notes practical deployment requires kernel-mode execution and signed or compromised drivers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
