Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.

UNCLASSIFIED
Pique Proof-of-Concept (PoC) Report
Anti-Debugging and Anti-Emulation
Figure 4. ForceFlags Flag at offset 0x74 (Windows 10 64-bit)
(U) Checking the PEB NTGlobalFlag Value
(U) Another PEB element that contains information about whether the application was launched
under a debugger is the NTGlobalFlag. The NTGlobalFlag element offset in the PEB differs
between the 32-bit and 64-bit versions of Windows, as shown in Table 2.
Table 2. NTGlobalFlag Offset in PEB by OS Variety
Windows Variety NTGlobalFlag Offset in PEB
32-bit Versions (Win 8, 8.1, and 10) 0x068
64-bit Versions (Win 8, 8.1, and 10) 0x0bc
Raytheon Blackbird Technologies, Inc.
9
07 August 2015
Use or disclosure of data contained on this sheet is subject to the restrictions on the title page of this document.
UNCLASSIFIED

e-Highlighter

Click to send permalink to address bar, or right-click to copy permalink.

Un-highlight all Un-highlight selectionu Highlight selectionh