AN1593
Analytic 1593
Windows
Unexpected modification of the KernelCallbackTable in a process’s PEB followed by invocation of modified callback functions (e.g., fnCOPYDATA) through Windows messages. Defender observes suspicious API call chains such as NtQueryInformationProcess → WriteProcessMemory → abnormal GUI callback execution, often correlating to anomalous process behavior such as network activity or code injection.
WinEventLog:Sysmon
EventCode=10
WinEventLog:Sysmon
EventCode=1
etw:Microsoft-Windows-Kernel-Process
WriteProcessMemory: WriteProcessMemory targeting regions containing KernelCallbackTable addresses
[MonitoredProcesses]
GUI applications (e.g., explorer.exe, notepad.exe) where KernelCallbackTable abuse is more likely.
[CallbackFunctions]
Specific callback functions (e.g., fnCOPYDATA, fnDWORD) expected to remain stable.
[TimeWindow]
Correlation interval between WriteProcessMemory calls and execution of modified callback functions.
[AccessMaskThresholds]
Access rights values that should be flagged when targeting GUI processes.