Malicious Process Environment Block Manipulation, (Fri, Jan 9th)
ID: c2114780-2047-5787-ab6c-3a67e4087c10
STIX ID: report--c2114780-2047-5787-ab6c-3a67e4087c10
Feed Name: SANS ISC Diary
Threat Score
This diary-style technical write-up demonstrates how an attacker or malware can locate and modify a Windows process's PEB to overwrite the CommandLine buffer and hide or spoof process parameters; it provides proof-of-concept C code for both suspended-process modification and updating a running process, and discusses practical limitations (must not exceed original buffer length and EDRs may log original parameters at process creation).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
