{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2022:U5CGCQIY32YO74VPDG4EE5GQU4","short_pith_number":"pith:U5CGCQIY","schema_version":"1.0","canonical_sha256":"a744614118deb0eff2af19b84274d0a724e6b0e524ff1972835ed34d1dd0b308","source":{"kind":"arxiv","id":"2210.02821","version":1},"attestation_state":"computed","paper":{"title":"Microsoft Defender Will Be Defended: MemoryRanger Prevents Blinding Windows AV","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.OS"],"primary_cat":"cs.CR","authors_text":"Denis Pogonin, Igor Korkin","submitted_at":"2022-10-06T11:25:05Z","abstract_excerpt":"Windows OS is facing a huge rise in kernel attacks. An overview of popular techniques that result in loading kernel drivers will be presented. One of the key targets of modern threats is disabling and blinding Microsoft Defender, a default Windows AV. The analysis of recent driver-based attacks will be given, the challenge is to block them. The survey of user- and kernel-level attacks on Microsoft Defender will be given. One of the recently published attackers techniques abuses Mandatory Integrity Control (MIC) and Security Reference Monitor (SRM) by modifying Integrity Level and Debug Privile"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2210.02821","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2022-10-06T11:25:05Z","cross_cats_sorted":["cs.OS"],"title_canon_sha256":"467b54e481c145fd1b919d84ca6ca9330a657dc347be42907b0c88c33ac0cd84","abstract_canon_sha256":"4f38fdb21e1b09eb5907268f011c52c19b98dba75ccdec31361c51b4f62d84b4"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:03:57.463248Z","signature_b64":"ap4f+pyhG8Vv+lTLEbzx/lh8bdGcDFND4GvOx7D9s/Ht0GP9SFx1HrTUsvXtV7dE9AAMreTZ6k+H/zae6YZdBA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a744614118deb0eff2af19b84274d0a724e6b0e524ff1972835ed34d1dd0b308","last_reissued_at":"2026-07-05T05:03:57.462830Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:03:57.462830Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Microsoft Defender Will Be Defended: MemoryRanger Prevents Blinding Windows AV","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.OS"],"primary_cat":"cs.CR","authors_text":"Denis Pogonin, Igor Korkin","submitted_at":"2022-10-06T11:25:05Z","abstract_excerpt":"Windows OS is facing a huge rise in kernel attacks. An overview of popular techniques that result in loading kernel drivers will be presented. One of the key targets of modern threats is disabling and blinding Microsoft Defender, a default Windows AV. The analysis of recent driver-based attacks will be given, the challenge is to block them. The survey of user- and kernel-level attacks on Microsoft Defender will be given. One of the recently published attackers techniques abuses Mandatory Integrity Control (MIC) and Security Reference Monitor (SRM) by modifying Integrity Level and Debug Privile"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2210.02821","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2210.02821/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2210.02821","created_at":"2026-07-05T05:03:57.462888+00:00"},{"alias_kind":"arxiv_version","alias_value":"2210.02821v1","created_at":"2026-07-05T05:03:57.462888+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2210.02821","created_at":"2026-07-05T05:03:57.462888+00:00"},{"alias_kind":"pith_short_12","alias_value":"U5CGCQIY32YO","created_at":"2026-07-05T05:03:57.462888+00:00"},{"alias_kind":"pith_short_16","alias_value":"U5CGCQIY32YO74VP","created_at":"2026-07-05T05:03:57.462888+00:00"},{"alias_kind":"pith_short_8","alias_value":"U5CGCQIY","created_at":"2026-07-05T05:03:57.462888+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2511.04472","citing_title":"Evading and crashing anti-malware solutions via data collection overloading during analysis serialization","ref_index":19,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/U5CGCQIY32YO74VPDG4EE5GQU4","json":"https://pith.science/pith/U5CGCQIY32YO74VPDG4EE5GQU4.json","graph_json":"https://pith.science/api/pith-number/U5CGCQIY32YO74VPDG4EE5GQU4/graph.json","events_json":"https://pith.science/api/pith-number/U5CGCQIY32YO74VPDG4EE5GQU4/events.json","paper":"https://pith.science/paper/U5CGCQIY"},"agent_actions":{"view_html":"https://pith.science/pith/U5CGCQIY32YO74VPDG4EE5GQU4","download_json":"https://pith.science/pith/U5CGCQIY32YO74VPDG4EE5GQU4.json","view_paper":"https://pith.science/paper/U5CGCQIY","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2210.02821&json=true","fetch_graph":"https://pith.science/api/pith-number/U5CGCQIY32YO74VPDG4EE5GQU4/graph.json","fetch_events":"https://pith.science/api/pith-number/U5CGCQIY32YO74VPDG4EE5GQU4/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/U5CGCQIY32YO74VPDG4EE5GQU4/action/timestamp_anchor","attest_storage":"https://pith.science/pith/U5CGCQIY32YO74VPDG4EE5GQU4/action/storage_attestation","attest_author":"https://pith.science/pith/U5CGCQIY32YO74VPDG4EE5GQU4/action/author_attestation","sign_citation":"https://pith.science/pith/U5CGCQIY32YO74VPDG4EE5GQU4/action/citation_signature","submit_replication":"https://pith.science/pith/U5CGCQIY32YO74VPDG4EE5GQU4/action/replication_record"}},"created_at":"2026-07-05T05:03:57.462888+00:00","updated_at":"2026-07-05T05:03:57.462888+00:00"}