
We all know Sysmon has many great features. But did you know, there is a hidden one that allows you to execute code in the kernel? Here's an example that disables lsass.exe's PPL! Many thanks to @SBousseaden for verifying.
Undev Ninja
1.5K posts

@0x00dtm
Software undevelopment

We all know Sysmon has many great features. But did you know, there is a hidden one that allows you to execute code in the kernel? Here's an example that disables lsass.exe's PPL! Many thanks to @SBousseaden for verifying.


Join me tomorrow at 2PM UTC in OnlyMalware as part of a new series where I look to explore leaked malware code bases. This week we will start with the infamous Conti source code leak. I'm looking forward to seeing y'all there! discord.gg/onlymalware?ev…


I have uploaded the recording to YouTube of the Conti Source Code analysis, exploring the encryptor code base. We cover various functionality implementation and oppurtunities for improvement/detection. youtu.be/SGbhqwXB-GU










