Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
UNCLASSIFIED
Pique PoC Outline
Direct Kernel Object Manipulation (DKOM)
UNCLASSIFIED
Figure 4. (U) Windows 8 64-bit – Offset to ActiveProcessLinks
We will then call WriteKernelMemory(), which is a wrapper function for
ZwSystemDebugControl(), to modify the FLINK and BLINK to effectively hide the target
process.
Raytheon Blackbird Technologies, Inc.
7
21 November 2014
Use or disclosure of data contained on this sheet is subject to the restrictions on the title page of this document.
UNCLASSIFIED