← ./resources / blog

Module Stomping: When a Trusted Mapping Stops Being Trusted

Module stomping places unexpected code over part of a legitimately mapped image. A module name and valid disk signature can therefore describe provenance without proving that every executable page still matches the signed file.

Defensive scope

This guide covers integrity validation and response. It does not explain how to select, overwrite, or execute within a target module.

The trust mismatch

Windows maps executable image sections from files, often sharing clean pages until a write causes a private copy. If code bytes are modified, the process can retain a plausible module path while some pages no longer match the signed image. Defenders need page-level provenance: mapping type, protection history, copy-on-write state, hash comparison, and the threads or stacks that reach the changed region.

A trusted file name does not guarantee page integritySigned DLLon diskImage mappingin processClean pagesChanged pageThread orstack reaches itValidate by page, section, version, relocation state, hotpatch policy, signer, and execution evidence
Integrity checking must account for relocations and legitimate hotpatching before classifying a difference.

Detection and triage

  • Compare executable image pages to the exact on-disk version after normal relocations.
  • Identify copy-on-write executable pages and recent protection changes.
  • Determine whether differences fall in code, padding, hotpatch, or data regions.
  • Find threads starting or repeatedly executing inside changed ranges.
  • Correlate the writer process, handle rights, target role, and later behavior.

Known patching frameworks, profilers, EDR hooks, anti-cheat systems, and application hotpatches can alter code legitimately. Establish vendor-specific baselines and verify digital signatures, deployment records, and expected patch locations.

Tools and safe exercise

PE-sieve, Moneta, Volatility 3, and pefile support comparison and triage. In an isolated lab, compare a clean application before and after an approved profiler or instrumentation product modifies it. Document the expected pages and stacks; use those observations to prevent a simplistic “any changed page” alert.

ATT&CK, CVEs, and controls

Module stomping commonly maps to T1055. Module Stomping and PE image mapping are techniques and mechanisms, not CVEs. A separate software flaw may provide access in a real intrusion and should be tracked independently. Use WDAC, least privilege, EDR self-protection, code-integrity policy, protected processes where applicable, and page-level memory telemetry on high-value endpoints.

← Previous: Special APCNext: KernelCallbackTable →