Comment I'm curious. (Score 4, Interesting) 31
This sounds like it was written by someone who actually knows what they are doing, so I assume that they know better than I; but I am surprised to hear that it is impersonating a system dll; since (in all comparatively recent windows versions) system components are signed. Absolutely tons of fuckery you can do to them and around them; but if dpapi.dll doesn't have a signature that checks out the mechanisms that try to keep OSes up and running on marginal hardware subject to random power loss will likely eventually object and attempt a repair, even if there isn't any more paranoid EDR tooling in place.
Is the on-disk copy of dpapi.dll untouched and only the in-memory instance tampered with?
Is the on-disk copy of dpapi.dll untouched and only the in-memory instance tampered with?