94 karma · joined November 13, 2025
2072 80F 001612B0 ZwMapViewOfSection
2073 810 00163160 ZwMapViewOfSectionEx
> PS C:\Program Files\Microsoft Visual Studio\18\Community> dumpbin.exe /EXPORTS C:\Windows\System32\ntdll.dll | rg NtMapViewOfSection 425 1A0 001612B0 NtMapViewOfSection
426 1A1 00163160 NtMapViewOfSectionEx
> How "differently" exactly? That's undocumented.https://learn.microsoft.com/en-us/windows-hardware/drivers/k...
I can only wonder where `NtMapViewOfSection` could be exported from...
> If the call to this function occurs in user mode, you should use the name "NtMapViewOfSection" instead of "ZwMapViewOfSection".
Should be pretty difficult to ignore
Outside of DEFCON I think this is an interesting article: https://osec.io/blog/save-ctfs-fund/
https://k0mkc.hatenablog.com/entry/2026/08/06/032440
Mind you, odds are their anti-tamper/DRM is a different case.
> As AI assisted static deobfuscation continues to improve we will see more virtual machine based obfuscators fold away. In an upcoming article we will publish details on how we fully statically devirtualized Denuvo anti(tamper/cheat). One of the most attacked pieces of software second only to anticheats.
…or you can not bother with analyzing at all and just feed correct CPUID/shared data/whatever values to Denuvo, like the hypervisor thing does.
I’m sure there are more open source examples. A newer one is https://github.com/namazso/PawnIO/tree/master I guess?
Getting your driver signed seems like a pain these days, yeah
Okay so it’s worse than Opus 4.8 for my purposes I guess?
And given the whining on UC it seems to be fairly effective.