Skip to content

Research Notes

Kriyos Arcane edited this page Jul 4, 2026 · 1 revision

Research Notes

Extra findings that shaped the shipped set live here.

Closed Leads

  • mso.dll DLL search-order SIP hijack. Tested on Win10 22H2. WINTRUST.DLL was already loaded through the import table before SIP registry lookup happened. LoadLibrary returned the existing handle. Search order never fired.
  • CryptDllDecodeObjectEx for auto-execution. Registration required SYSTEM, and WinVerifyTrust never called it for the target OIDs.
  • SIP hijack for catalog-signed binaries. The catalog path bypassed SIP dispatch for the PE.
  • Trust Provider Message step with SoftpubCleanup. Result was a null signer, not a bypass.

Architecture Decisions

  • SIP hijack defaults to PE, PowerShell, and MSI. This keeps the registry footprint small and trims detection surface.
  • FinalPolicy uses $DLL and $Function. SIP keys use Dll and FuncName. Early builds that mixed them failed silently.
  • The C++ tool uses static linking with -static. Target hosts lacked the MinGW C++ runtime DLLs. Without static linking, the tool produced no output over SSH.
  • Trust Provider keys and SIP keys use different value names. Mixing the two breaks the install path without a visible error.

Technique Variations Not Shipped

  • Dual-SignerInfo emitter. Place the payload in a second SignerInfo instead of unsignedAttrs. Kernel-mode readers tend to consume index [0], while user-mode parsers often walk the full set. This stays research-grade and needs more lab time.
  • Publisher name spoofing. A self-signed cert with a chosen CN, plus TrustedPublisher enrollment and FinalPolicy hijack, makes UAC show the chosen publisher. This remains experimental.
  • Payload encryption for SigStash. XOR or AES over the OCTET STRING blocks future content scanning. The current tool leaves payloads plaintext.
  • AMSI provider hijack. Similar registry DLL redirection exists on the AMSI side. This path remains untested.

Clone this wiki locally