Skip to content

No Alter_context RPC call for IID: ISpeechNamedPipe? #1

@hsportel

Description

@hsportel

Just trying to understand the underlying technique here, as seen with the bitlockmove you can see in the pcap the RPC Alter_context call for IID IBDEUILauncher (8961f0a0-ff62-403b-91b4-7b9280241ceb). So i was expecting to see this call also for IID: ISpeechNamedPipe (67C43788-DFDE-464E-BAA1-5AFA424895FD) in this POC... but there isn't any?

The POC is working by the way, executed both from windows server or win11, but how different is this from the bitlockmove? Maybe someone is willing to do some explaining? :)

Image

From the bitlockmove poc, you can see the alter_context RPC call for the IID IBDEUILauncher, but there is no call for the IID ISpeechNamedPipe..

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions