all InfoSec news
RustChain - Hide Memory Artifacts Using ROP And Hardware Breakpoints
KitPloit - PenTest Tools! www.kitploit.com
This tool is a simple PoC of how to hide memory artifacts using a ROP chain in combination with hardware breakpoints. The ROP chain will change the main module memory page's protections to N/A while sleeping (i.e. when the function Sleep is called). For more detailed information about this memory scanning evasion technique check out the original project Gargoyle. x64 only.
The idea is to set up a hardware breakpoint in kernel32!Sleep and a new top-level filter to …
artifacts breakpoints called change function hardware hide information main memory poc redteam rop rop chain rustchain scans simple sleep sleeping tool