Windows Notification Facility - Peeling the Onion of the Most Undocumented Kernel Attack Surface Yet
Offered By: Black Hat via YouTube
Course Description
Overview
Syllabus
Intro
About Alex lonescu
What is WNF?
Why does WNF exist?
State Name Lifetime
State Scopes
Sequence Numbers
Registering a WNF State Name
Publishing WNF State Data
Consuming WNF Data
WNF Notifications
High Level API
Notification Callback
Kernel API
WNF Name Instance
WNF Scope Instance
WNF Scope Map
WNF Subscription
WNF Process Context
WinDBG Custom Extension
The O-byte Write
The Privileged Disclosure
The Modern App Launcher Blocker
The Crashing Service
Discovering State Names and Permissions
Discovering Volatile Names
Brute Forcing Security Descriptors
Creating custom WNF State Names
EDR/AM Visibility Options
Controlling the System with WNF
Interesting Insider Settings
Injecting Code with WNF
Modifying Callbacks/Contexts for Code Redirection
Key Takeaways
Taught by
Black Hat
Related Courses
Rootkits and Stealth Apps: Creating & Revealing 2.0 HACKINGUdemy Game Hacking: Cheat Engine Game Hacking Basics
Udemy Reverse Engineering and Memory Hacking with Cheat Engine
Udemy The Evolution of the Software Supply Chain Attack
Pluralsight Web Security
Stanford University via YouTube