<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Decompiler-Artifact on Leandro&#39;s Code Cave</title>
    <link>https://iamleandrooooo.github.io/tags/decompiler-artifact/</link>
    <description>Recent content in Decompiler-Artifact on Leandro&#39;s Code Cave</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 10 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://iamleandrooooo.github.io/tags/decompiler-artifact/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Refuting a condrv Kernel Read - Chasing a COMPLETE_IO memmove Through the Console IPC and a Self-Verifying PoC, Only to Lose to One Decompiler-Hidden ProbeForRead on Windows 11 24H2</title>
      <link>https://iamleandrooooo.github.io/posts/the-arbitrary-kernel-read-that-wasnt/</link>
      <pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://iamleandrooooo.github.io/posts/the-arbitrary-kernel-read-that-wasnt/</guid>
      <description>1. Why the console driver is an attack surface at all condrv.sys is the Console Driver. Since the Windows 7-era console rewrite (and especially post-Windows 10, when the console host moved out of csrss into conhost.exe), condrv is the kernel broker sitting between a console client (your cmd.exe, your powershell.exe - anything with a console) and a console server (conhost.exe). Every ReadConsole, WriteConsole, and the whole console-handle machinery is marshalled through it.</description>
    </item>
  </channel>
</rss>
