GET /api/techniques/63/
HTTP 200 OK
Allow: GET, PUT, PATCH, DELETE, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "name": "NtGlobalFlag",
    "category": [
        "https://search.unprotect.it/api/categories/3/"
    ],
    "description": "The information that the system uses to determine how to create heap structures is stored at an undocumented location in the PEB at offset 0x68. If the value at this location is 0x70, we know that we are running in a debugger.",
    "resources": "https://www.aldeid.com/wiki/PEB-Process-Environment-Block/NtGlobalFlag",
    "tags": "",
    "snippets": [
        {
            "language": "https://search.unprotect.it/api/snippet_languages/2/",
            "author": "https://search.unprotect.it/api/snippet_authors/6/",
            "technique": "https://search.unprotect.it/api/techniques/63/",
            "description": "",
            "plain_code": "#include <Winternl.h>\r\n#include <Windows.h>\r\n#include <tchar.h>\r\n#include <stdio.h>\r\n\r\n/*\r\n*Using ZwQueryInformationProcess we get the PEB Address and \r\n*then we check the NtGlobalFlag to determine the process is being debugged or not.\r\n*/\r\n\r\nint main() {\r\n     \r\n    typedef unsigned long(__stdcall *pfnZwQueryInformationProcess)\r\n    (\r\n        IN  HANDLE,\r\n        IN  unsigned int, \r\n        OUT PVOID, \r\n        IN  ULONG, \r\n        OUT PULONG\r\n    );\r\n    pfnZwQueryInformationProcess ZwQueryInfoProcess = NULL;\r\n     \r\n    HMODULE hNtDll = LoadLibrary(_T("ntdll.dll"));\r\n    if (hNtDll == NULL) { }\r\n \r\n    ZwQueryInfoProcess = (pfnZwQueryInformationProcess) GetProcAddress(hNtDll,\r\n        "ZwQueryInformationProcess");\r\n    if (ZwQueryInfoProcess == NULL) { }\r\n    unsigned long status;\r\n \r\n    DWORD pid = GetCurrentProcessId();\r\n    HANDLE hProcess = OpenProcess(PROCESS_QUERY_INFORMATION, FALSE, pid);\r\n    PROCESS_BASIC_INFORMATION pbi;\r\n    status = ZwQueryInfoProcess(hProcess,\r\n                                ProcessBasicInformation,\r\n                                &pbi,\r\n                                sizeof(pbi),\r\n                                NULL);\r\n                                 \r\n    PPEB peb_addr = pbi.PebBaseAddress;\r\n    DWORD ptr = pbi.PebBaseAddress;\r\n    ptr|=104;\r\n    DWORD *temp = ptr;\r\n    MessageBox(0, *temp ? "Debugger found" : "Debugger not found","Status",0x30);\r\n     \r\n    return 0;\r\n}"
        }
    ],
    "detection_rules": [
        {
            "type": "https://search.unprotect.it/api/detection_rule_categories/1/",
            "name": "DebuggerCheck__GlobalFlags",
            "rule": "rule DebuggerCheck__GlobalFlags  {\r\n    meta:\r\n\tdescription = \"Rule to detect NtGlobalFlags debugger check\"\r\n        author = \"Thibault Seret\"\r\n        date = \"2020-09-26\"\r\n    strings:\r\n        $s1 = \"NtGlobalFlags\"\r\n    condition:\r\n        any of them\r\n}"
        },
        {
            "type": "https://search.unprotect.it/api/detection_rule_categories/2/",
            "name": "ntglobalflag",
            "rule": "rule:\r\n  meta:\r\n    name: check for PEB NtGlobalFlag flag\r\n    namespace: anti-analysis/anti-debugging/debugger-detection\r\n    author: moritz.raabe@fireeye.com\r\n    scope: function\r\n    mbc:\r\n      - Anti-Behavioral Analysis::Debugger Detection::Process Environment Block NtGlobalFlag [B0001.036]\r\n    references:\r\n      - Practical Malware Analysis, Chapter 16, p. 355\r\n      - https://www.geoffchappell.com/studies/windows/win32/ntdll/structs/peb/index.htm\r\n    examples:\r\n      - Practical Malware Analysis Lab 16-01.exe_:0x403530\r\n  features:\r\n    - and:\r\n      - basic block:\r\n        - and:\r\n          - match: PEB access\r\n          - or:\r\n            - or:\r\n              - offset/x32: 0x68 = PEB.NtGlobalFlag\r\n              - offset/x64: 0xBC = PEB.NtGlobalFlag\r\n            - and:\r\n              - mnemonic: add\r\n              - or:\r\n                - number/x32: 0x68 = PEB.NtGlobalFlag\r\n                - number/x64: 0xBC = PEB.NtGlobalFlag\r\n      - number: 0x70 = (FLG_HEAP_ENABLE_TAIL_CHECK | FLG_HEAP_ENABLE_FREE_CHECK | FLG_HEAP_VALIDATE_PARAMETERS)"
        }
    ]
}