Vault 7: Projects

This publication series is about specific projects related to the Vault 7 main publication.
UNCLASSIFIED
Pique PoC Outline
Direct Kernel Object Manipulation (DKOM)
and Windows 8 64-bit are in Table 1 and shown in the Windows windbg screen capture in
Figures 3 and 4.
Table 1. (U) Offsets to ActiveProcessLinks
OS Offset to ActiveProcessLinks
Windows 7 32-bit 0x0b8
Windows 8 64-bit 0x2e8
UNCLASSIFIED
UNCLASSIFIED
Figure 3. (U) Windows 7 32-bit – Offset to ActiveProcessLinks
Raytheon Blackbird Technologies, Inc.
6
21 November 2014
Use or disclosure of data contained on this sheet is subject to the restrictions on the title page of this document.
UNCLASSIFIED