-
Notifications
You must be signed in to change notification settings - Fork 17
Research Notes
Kriyos Arcane edited this page Jul 4, 2026
·
1 revision
Extra findings that shaped the shipped set live here.
-
mso.dllDLL search-order SIP hijack. Tested on Win10 22H2.WINTRUST.DLLwas already loaded through the import table before SIP registry lookup happened.LoadLibraryreturned the existing handle. Search order never fired. -
CryptDllDecodeObjectExfor auto-execution. Registration requiredSYSTEM, andWinVerifyTrustnever called it for the target OIDs. - SIP hijack for catalog-signed binaries. The catalog path bypassed SIP dispatch for the PE.
- Trust Provider Message step with
SoftpubCleanup. Result was a null signer, not a bypass.
- SIP hijack defaults to PE, PowerShell, and MSI. This keeps the registry footprint small and trims detection surface.
- FinalPolicy uses
$DLLand$Function. SIP keys useDllandFuncName. Early builds that mixed them failed silently. - The C++ tool uses static linking with
-static. Target hosts lacked the MinGW C++ runtime DLLs. Without static linking, the tool produced no output over SSH. - Trust Provider keys and SIP keys use different value names. Mixing the two breaks the install path without a visible error.
- Dual-SignerInfo emitter. Place the payload in a second
SignerInfoinstead ofunsignedAttrs. Kernel-mode readers tend to consume index[0], while user-mode parsers often walk the full set. This stays research-grade and needs more lab time. - Publisher name spoofing. A self-signed cert with a chosen CN, plus
TrustedPublisherenrollment and FinalPolicy hijack, makes UAC show the chosen publisher. This remains experimental. - Payload encryption for SigStash. XOR or AES over the
OCTET STRINGblocks future content scanning. The current tool leaves payloads plaintext. - AMSI provider hijack. Similar registry DLL redirection exists on the AMSI side. This path remains untested.