meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 18 September 2025

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Thursday, September 18th, 2025: DLL Hooking; Entra ID Actor Tokens; Watchguard and NVidia Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, September 18th, 2025 edition of the Sands Internet Storms Centers.

0:12.3

Stormcast, my name is Johannes Ulrich, recording today from Jacksonville, Florida.

0:18.1

And this episode is brought you by the Sands.edu graduate certificate program in incident response.

0:26.4

Well, in Diaries today, we do have Xavier talk about Control C DLL hooking. The trick that Xavier is

0:36.1

referring to here is, well, first of all, if you are

0:39.1

reverse analyzing malware, you're trying to introduce breakpoints into the code where you're

0:44.4

able to better analyze what's happening in particular segments of the code. The problem with this

0:51.1

is that you're going to modify some of the code in memory by essentially,

0:57.2

well, adding these software breakpoints to specific API calls.

1:02.2

Now, Malware has a couple different options here in order to bypass this.

1:07.3

They can, like, check whether or not these breakpoints are present.

1:11.0

That's a little bit tricky because they have to go through all the different possible

1:13.8

API calls that you may have added these breakpoints to.

1:18.3

But a simpler solution, it just reloads the code from a disk for that particular DL

1:24.9

with that overriding any modifications that may have made after the DL was loaded into memory.

1:31.4

And that's exactly what Xavier illustrates here and how it is being done in a particular malware sample that Xavi came across.

1:39.2

This malware sample appears to be some prototype not quite finished yet ransomware that's written in

1:46.2

Python so interesting that aspect as well and it just performs this simple trick where it reloads

1:54.5

the DLL in order to basically invalidate whatever breakpoint or other modifications an analyst may have made.

2:04.8

And we got an interesting blog post by Derek Yan Molima about a vulnerability that

2:09.8

Derek Yan did disclose to Microsoft and which was addressed as part of this September's patch Tuesday.

2:19.3

This wasn't Azure vulnerability, so nothing that you have to patch.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.