Module Stomping: When a Trusted Mapping Stops Being Trusted
Module stomping places unexpected code over part of a legitimately mapped image. A module name and valid disk signature can therefore describe provenance without proving that every executable page still matches the signed file.
This guide covers integrity validation and response. It does not explain how to select, overwrite, or execute within a target module.
The trust mismatch
Windows maps executable image sections from files, often sharing clean pages until a write causes a private copy. If code bytes are modified, the process can retain a plausible module path while some pages no longer match the signed image. Defenders need page-level provenance: mapping type, protection history, copy-on-write state, hash comparison, and the threads or stacks that reach the changed region.
Detection and triage
- Compare executable image pages to the exact on-disk version after normal relocations.
- Identify copy-on-write executable pages and recent protection changes.
- Determine whether differences fall in code, padding, hotpatch, or data regions.
- Find threads starting or repeatedly executing inside changed ranges.
- Correlate the writer process, handle rights, target role, and later behavior.
Known patching frameworks, profilers, EDR hooks, anti-cheat systems, and application hotpatches can alter code legitimately. Establish vendor-specific baselines and verify digital signatures, deployment records, and expected patch locations.
Tools and safe exercise
PE-sieve, Moneta, Volatility 3, and pefile support comparison and triage. In an isolated lab, compare a clean application before and after an approved profiler or instrumentation product modifies it. Document the expected pages and stacks; use those observations to prevent a simplistic “any changed page” alert.
ATT&CK, CVEs, and controls
Module stomping commonly maps to T1055. Module Stomping and PE image mapping are techniques and mechanisms, not CVEs. A separate software flaw may provide access in a real intrusion and should be tracked independently. Use WDAC, least privilege, EDR self-protection, code-integrity policy, protected processes where applicable, and page-level memory telemetry on high-value endpoints.