Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

UNCLASSIFIED
Pique Proof-of-Concept (PoC) Report
Anti-Debugging and Anti-Emulation
(U) If the value of the NTGlobalFlag is 0x70, the application is being debugged as can be seen in
Figure 5. The value of 0x70 is a combination of three separate flags being set when a heap is
created by a debugger. The three flags set when a heap is created by a debugger are
FLG_HEAP_ENABLE_TAIL_CHECK (0x10), FLG_HEAP_ENABLE_FREE_CHECK (0x20),
and FLG_HEAP_VALIDATE_PARAMETERS (0x40).
Figure 5. NTGlobalFlag – 64-bit Application Being Debugged
Raytheon Blackbird Technologies, Inc.
10
07 August 2015
Use or disclosure of data contained on this sheet is subject to the restrictions on the title page of this document.
UNCLASSIFIED

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh