#kASLR

2025-06-16
I created a library from prefetch-tool so you can more easily experiment with side-channel #KASLR bypasses on Windows:

https://github.com/v-p-b/prefetch-lib

For dogfooding I exploited HEVD on Windows 11 24H2:

https://github.com/v-p-b/HEVD-prefetch
kriware :verified:kriware@infosec.exchange
2025-05-27

Bypassing kASLR via Cache Timing

Explores a prefetch side-channel attack to bypass kASLR on Windows 11 by measuring cache access times to locate the kernel base address.

r0keb.github.io/posts/Bypassin

#kASLR #SideChannel

2024-04-28

#Exploiting the #NT #Kernel in 24H2: New Bugs in Old Code & Side Channels Against #KASLR

exploits.forsale/24h2-nt-explo

2024-03-25

@mdhughes @Reiddragon this is oversimplifying by A LOT. For instance: some desktop things work better on #OpenBSD than #FreeBSD. #NetBSD was the first #BSD to implement #KASLR - before OpenBSD. It's not black and white and hasn't been for years now yet everybody copies the same fake mantras about these 3 BSDs.

2022-11-24

A new ETW event, […] that could point at various suspicious behaviors of #KASLR bypasses

#offensivesecurity #redteam #blueteam #windowssecurity #edr

windows-internals.com/an-end-t

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst