Dirty Vanity: A New Approach to Code Injection & EDR Bypass

No ratings

Presented at BlackHat Europe 2022 by

This talk showcases yet another new code injection technique (I know, bear with me), nicknamed "Dirty Vanity". This technique challenges current injection detection and prevention means while opening a wider spectrum of attacks that challenges common concepts of EDR TTPs.This technique abuses the lesser-known forking mechanism which is built in Windows operating systems.In the talk, we will cover the forking mechanism's internals, and common means to activate it. We will discuss legitimate usage of it, and mention a known malicious usage for LSASS credential dumping. Finally, we will present Dirty Vanity and the research behind it, how it works, and its implications on current detection methods.