Windows Exploit Mitigation Series - Reversing Export Address Table Filtering (EAF)

Опубликовано: 17 Апрель 2026
на канале: Off By One Security
1,199
66

Note: This stream was a bit choppy, and so I rerecorded another version that should be better quality. You can watch it here:    • Windows Exploit Mitigation Series: Reversi...  

Join me in this stream where I will reverse engineer another mitigation from Windows Defender Exploit Guard, called Export Address Table Filtering (EAF). So far in this series, we've looked at Stack Pivot Protection, Do Not Allow Child Processes, Isolated Heaps, and Heap Spray Protection. This particular mitigation, EAF, is one that I'm quite interested in understanding at a lower level as its aimed at preventing shellcode from accessing the exports table of specific DLL's. We may fumble a bit along the way, but will leave with a clear understanding as to how this mitigation works, which is important when wanting to try and come up with bypass techniques. Bring on the demo gods!