Skip to content

Commit

Permalink
Update README.md
Browse files Browse the repository at this point in the history
  • Loading branch information
thomasxm authored Jul 12, 2024
1 parent 298aa3f commit 6c654d3
Showing 1 changed file with 2 additions and 1 deletion.
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -218,6 +218,8 @@ options:
## New Memory Guard
<img width="400" alt="Sifu" src="https://github.com/user-attachments/assets/935ee41b-02cd-46dc-8d29-2fd67d365b7f">
### Introduction
Due to the prevalence of Kernel PatchGuard, System Service Descriptor Table (SSDT) hooking has become less popular among AV companies. Userland hooks and kernel callback inspection are the two main methods adopted by contemporary AVs.
Expand All @@ -244,7 +246,6 @@ Marcus proposed using hardware breakpoints to set up the function arguments at t
### New Memory Guard Family:
<img width="400" alt="Sifu" src="https://github.com/user-attachments/assets/935ee41b-02cd-46dc-8d29-2fd67d365b7f">
The aim is to make the shellcode "non-exist" to the AV as long as possible except when it is executed in a thread.
Expand Down

0 comments on commit 6c654d3

Please sign in to comment.