Hey kernelmode,
I've successfully bypassed UAC restrictions with a technique found by this guy:
http://www.pretentiousname.com/misc/W7E ... tails.html
But when I try to make the same thing on windows 8.1(not with sysprep.exe of course), my.dll is successfully mmaped in .exe autoelevated, but then process returns 0xc000007b error, this guy managed to do it in windows 8.1:
http://blog.cobaltstrike.com/2014/03/20 ... ould-know/
So my question is, are autoelevated processes doing some kind of extracheck for whitelisted dlls or something?
I've successfully bypassed UAC restrictions with a technique found by this guy:
http://www.pretentiousname.com/misc/W7E ... tails.html
But when I try to make the same thing on windows 8.1(not with sysprep.exe of course), my.dll is successfully mmaped in .exe autoelevated, but then process returns 0xc000007b error, this guy managed to do it in windows 8.1:
http://blog.cobaltstrike.com/2014/03/20 ... ould-know/
So my question is, are autoelevated processes doing some kind of extracheck for whitelisted dlls or something?