Further reading
- Egg hunting:
http://www.hick.org/code/skape/papers/egghunt-shellcode.pdf
- MSFVenom – Looking for
WaitForSingleObject
calls:
https://www.notion.so/Looking-for-WaitForSingleObject-Call-in-Modern-Metasploit-Shellcode-570fdaad2e32446eb8725e07c6c96125
- Blackhat – Taking Windows 10 kernel exploitation to the next level:
https://www.blackhat.com/docs/us-17/wednesday/us-17-Schenk-Taking-Windows-10-Kernel-Exploitation-To-The-Next-Level%E2%80%93Leveraging-Write-What-Where-Vulnerabilities-In-Creators-Update.pdf
- Windows architecture:
https://blogs.msdn.microsoft.com/hanybarakat/2007/02/25/deeper-into-windows-architecture/