Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[Defend] Identify and exclude 24H2+ hotpatch extension pages from sto…
…mp detection (elastic#192490) ## Release Note Defend 8.15.2 will improve support for [Windows call stack module stomp detection](https://www.elastic.co/security-labs/upping-the-ante-detecting-in-memory-threats-with-kernel-call-stacks) in Windows 11 24H2. ## Description Windows 11 24H2 adds hotpatch support, a great feature that enables the installation of many security updates without a system reboot. To implement hotpatching, Microsoft is changing the layout of executable images in memory, appending new "extension pages" to the end of every hotpatchable mapped image in memory. These pages are `PAGE_EXECUTE_READ`. data:image/s3,"s3://crabby-images/398ea/398eafb371b35737d9d09c732a67f1d3edb700f8" alt="image" Microsoft describes the change in some detail [here](https://techcommunity.microsoft.com/t5/windows-os-platform-blog/hotpatching-on-windows/ba-p/2959541). Here's a [third-party analysis of the change](https://ynwarcs.github.io/Win11-24H2-CFG) showing how it breaks x64debug. data:image/s3,"s3://crabby-images/cbcd5/cbcd59d15e4f331e6cdae8231fe683e06051562d" alt="image" Unfortunately, this change affects our module stomp detection feature, which views these executable pages as patched/stomped. We are fixing this in 8.15.2. This PR lets users opt out of the change, reverting to the old behavior. ### Checklist Delete any items that are not applicable to this PR. - [x] Any text added follows [EUI's writing guidelines](https://elastic.github.io/eui/#/guidelines/writing), uses sentence case text and includes [i18n support](https://github.com/elastic/kibana/blob/main/packages/kbn-i18n/README.md) ### For maintainers - [ ] This was checked for breaking API changes and was [labeled appropriately](https://www.elastic.co/guide/en/kibana/master/contributing.html#kibana-release-notes-process)
- Loading branch information