Phantom Code Evading Windows 11 25H2 Through Posix Based Self Deletion And Stealth Injection
About this talk
This talk covers the significant impact of Windows 11 24H2 on malware self-deletion techniques and the challenges it poses for penetration testing. Jakkaraju Varshith and Vivek Joshi from Rashtriya Raksha University explain how the changes to the NTFS driver have made previous self-deletion methods ineffective, leading to recoverable files during forensic analysis. They discuss leveraging the `FILE_DISPOSITION_POSIX_SEMANTICS` flag, originally intended for Windows Subsystem for Linux, to achieve complete and traceless file deletion, as well as the creation of an evasion chain through process injection into explorer.exe to bypass static signature detection.
More from this event
See all 28 talks →
Ai, Deception And Deepfakes When Trust Becomes The Primary Attack Surface
36:15
Cloud Resilience Simplified Less Data, Stronger Security
33:14
Demystifying Driver Research A Systematic Approach For Vulnerability Hunting
25:24
Dpdpa In Action Designing A 72 Hour Breach Response That Actually Works
22:56