ktapi.sys
ktapi.sys is a legacy cross-signed Kontron Technology Application Programming Interface driver that exposes the \\.\ktapi device to user mode. IOCTL 0x82007000 accepts a caller-controlled interface type, bus address, and size before using HalTranslateBusAddress, ZwOpenSection, and ZwMapViewOfSection to map physical memory into the calling process. Certain interface types cause HalTranslateBusAddress to return the supplied address unchanged, allowing an attacker to map arbitrary system RAM for physical-memory read and write. Expel documented this primitive in an EDR-killer exploit used by The Gentlemen ransomware group to obtain kernel code execution and terminate security processes.
Known samples 3
0 recorded TRUE · 0 recorded FALSE · 3 unknown for loading despite HVCI. Results apply to individual samples.
ktapi.sysSample 1 · HVCI unknown
- MD5
96a8b9db2dc9cba8cdf90c7c33fe11c4- SHA1
86c85f4cbc36377d6fdb3f2af7d3049d5174c62c- SHA256
7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237- Imphash
70988f60e2fd3f3d7776089a737aece5- Authentihash MD5
7b6216d216bfa67fd891f220599768ee- Authentihash SHA1
fb2670420e6096cda9c873d7dc4199de3b2ea870- Authentihash SHA256
5936c769202e628091702af98691e8ee838bf0acbefba7731322457f254665de- Machine
- AMD64
- Version
- 1.0.1899 built by: WinDDK
- Publisher
- Kontron Technology A/S
ktapi.sysSample 2 · HVCI unknown
- MD5
2c10be1aea72b7bdf07c735a4ad68876- SHA1
8b5cf43fba2c2226e6146ee065490dad17acc820- SHA256
9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046- Imphash
70988f60e2fd3f3d7776089a737aece5- Authentihash MD5
8f02305dfbeb3df6ee48156fde37ab2f- Authentihash SHA1
da72619db2843aa91e5ba8b3467386e194f93c18- Authentihash SHA256
646a91c588bd5f0f2e7649723297211efec1fcbe92f44f4b3b8858350beaa402- Machine
- AMD64
- Version
- 1.0.2118 built by: WinDDK
- Publisher
- Kontron Technology A/S
ktapi.sysSample 3 · HVCI unknown
- MD5
e3c123a2ee4720001ed35d45fa1e57eb- SHA1
92f5c4fd5791db408fa801fd3d887870691af1f8- SHA256
89ba754861e11d9db4440b2b5db61fd5bee16752e4623c4271b8fdd0a666c677- Imphash
ec4687bc52f296b7dcdfa7967aecbc0c- Authentihash MD5
fe3896c6129dd0b564f5051dbc80fb79- Authentihash SHA1
cc7b39806e076b266aabff1a7ca1e8cb62ca19dc- Authentihash SHA256
11101d0bf398ae0631904fff00431e0f23c0b13ca47055cafd797b2b48a6d44e- Machine
- I386
- Version
- 1.0.2118 built by: WinDDK
- Publisher
- Kontron Technology A/S
Recorded command
sc.exe create ktapi binPath=C:\windows\temp\ktapi.sys type=kernel && sc.exe start ktapiMap arbitrary physical memory from user mode for kernel read/write and defense impairment. · Privileges: kernel · OS: Windows 10, Windows 11
Research & references
Acknowledgement: Aaron Walton @AaronWalton

