Category

Posts

8 articles

PgC: Garbage collecting Patchguard away

I have released another article about Patchguard almost 5 years ago, ByePg, which was about exception hooking in the kernel, but let’s be frank, it didn’t entirely get rid of Patchguard; in this article I will be discussing an …

Splitting Data from Code, Forgotten x86 Feature: Segmentation

With the introduction of sTLB with Intel Nehalem, TLB splitting – once a reliable technique – became a thing of the past. Those who had to hook user-mode stealthily started looking into hypervisors; specifically EPT violations. …