Uploaded July 2026 | Updated September 2026, 3 weeks ago
Stack spoofing is a sophisticated technique that manipulates a thread's call stack so that code execution appears to originate from a different, benign location. In 2023, with StackMoonwalk, we presented a novel approach to this that slipped through common stack-based detection logic. Since then, we've watched defenders build on that research to expand telemetry and design more robust detectors. At the same time, we've seen increased adoption of hardware-backed mitigations (HSP|CET), which could offer another source of truth to spot this technique. Two years later, we asked ourselves whether it was finally time for stack spoofing to die. Well... it wasn't.
The talk begins in today's non-HSP environments, exploring modern detection frameworks built on call stack analysis and showing how fragile assumptions make them easy to bypass in practice. As proof, we introduce a new technique based on Moonwalk and a new primitive, proxy frames, to exploit these gaps. However, as clever as these methods are, their ROP-based primitives are welcomed by a crash the moment HSP/CET comes into play.
This pushed our research back to square one: could stack spoofing be rebuilt to survive CET enforcement? The result is the first known CET-compliant stack spoofing framework (BYOUD), delivered in three functional variants across distinct execution architectures. We first demonstrate how the framework can alter call stack resolution without triggering CP exceptions and then introduce the State-Driven Indirect Execution Architecture (SDIE), which takes the concept further to achieve a full HSP bypass.
We will conclude our talk by outlining the key lessons learned throughout this research: why overreliance on any single, emerging mitigation is dangerous, and how fragile design assumptions in detection logic can turn into blind spots. We will also provide concrete strategies and countermeasures so defenders can build stronger, more resilient detection capable of catching the presented techniques.
By: Alessandro Magnosi | Senior Security Consultant, SpecterOps
blackhat.com/eu-25/briefings/schedule/?#ghost-in-the-stack-evolving-call-stack-spoofing-in-a-post-cet-era-48965
Stack spoofing is a sophisticated technique that manipulates a thread's call stack so that code execution appears to originate from a different, benign location. In 2023, with StackMoonwalk, we presented a novel approach to this that slipped through common stack-based detection logic. Since then, we've watched defenders build on that research to expand telemetry and design more robust detectors. At the same time, we've seen increased adoption of hardware-backed mitigations (HSP|CET), which could offer another source of truth to spot this technique. Two years later, we asked ourselves whether it was finally time for stack spoofing to die. Well... it wasn't.
The talk begins in today's non-HSP environments, exploring modern detection frameworks built on call stack analysis and showing how fragile assumptions make them easy to bypass in practice. As proof, we introduce a new technique based on Moonwalk and a new primitive, proxy frames, to exploit these gaps. However, as clever as these methods are, their ROP-based primitives are welcomed by a crash the moment HSP/CET comes into play.
This pushed our research back to square one: could stack spoofing be rebuilt to survive CET enforcement? The result is the first known CET-compliant stack spoofing framework (BYOUD), delivered in three functional variants across distinct execution architectures. We first demonstrate how the framework can alter call stack resolution without triggering CP exceptions and then introduce the State-Driven Indirect Execution Architecture (SDIE), which takes the concept further to achieve a full HSP bypass.
We will conclude our talk by outlining the key lessons learned throughout this research: why overreliance on any single, emerging mitigation is dangerous, and how fragile design assumptions in detection logic can turn into blind spots. We will also provide concrete strategies and countermeasures so defenders can build stronger, more resilient detection capable of catching the presented techniques.
By: Alessandro Magnosi | Senior Security Consultant, SpecterOps
blackhat.com/eu-25/briefings/schedule/?#ghost-in-the-stack-evolving-call-stack-spoofing-in-a-post-cet-era-48965






![Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)
Event Tracing for Windows (ETW) is a built-in Windows logging and tracing framework that collects system and application events, providing detailed visibility into whats happening on a machine. In security, ETW is widely leveraged as one of the key telemetry sources for modern Endpoint Detection and Response (EDR) products because of the wealth of data it provides.
This trace data is generated by components known as providers. While four types exist—Managed Object Format (MOF), Windows software trace preprocessor (WPP), Manifest-based, and TraceLogging—Microsoft generally recommends using the two modern variants: Manifest-based and TraceLogging providers [1].
However, a significant knowledge gap exists. While Manifest-based providers are relatively well-understood [2], information regarding TraceLogging providers remains scarce. Consequently, it is questionable whether the security community is truly maximizing ETWs full potential.
To bridge this gap and enable defenders to better leverage ETW, we will present our findings on TraceLogging providers in the latest Windows. We will cover how to work with them, highlight providers potentially useful for security (e.g., AttackSurfaceMonitor), and walk through practical use cases.
Asuka Nakajima | Senior Security Research Engineer, Elastic
https://blackhat.com/asia-26/briefings/schedule/?#hidden-telemetry-uncovering-tracelogging-etw-providers-youre-not-using-yet-51991 Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers Youre Not Using (Yet)](https://i.ytimg.com/vi/ubFcs1M62P4/mqdefault.jpg)



