{"id":2089,"date":"2017-08-29T01:12:48","date_gmt":"2017-08-29T07:12:48","guid":{"rendered":"https:\/\/www.supportpro.com\/blog\/?p=2089"},"modified":"2019-10-29T05:23:50","modified_gmt":"2019-10-29T11:23:50","slug":"ghosthook-a-kernel-level-threat-in-64-bit-windows-systems","status":"publish","type":"post","link":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/","title":{"rendered":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems"},"content":{"rendered":"<p>GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been designed to forbid the kernel of 64-bit versions of Windows operating systems from being patched, preventing attackers from executing malicious code or running rootkits at the kernel level.<\/p>\n<p>According to the researchers at CyberArk, GhostHook is neither an elevation nor an exploitation technique but a post-exploitation attack where the attacker has control over the compromised system. It provides the hacker with the ability to hook almost any piece of code running on the system.<\/p>\n<p><!--more--><\/p>\n<p><strong>How does GhostHook work?<\/strong><\/p>\n<p>The GhostHook target only those systems that running Intel PT (Processor Trace), which are designed to provide support in debugging operations and hunting malicious code.<\/p>\n<p>The attacker makes use of a hacking exploit or malware first to compromise a target machine and then deploy GhostHook. Once compromised, the attacker can install a rootkit in the machine&#8217;s kernel, which would be completely undetectable to 3rd party anti-virus and security products and invisible to Microsoft&#8217;s PatchGuard itself.<\/p>\n<p><strong>Is there a patch for this?<\/strong><\/p>\n<p>CyberArk researchers believes that the GhostHook may be extremely difficult for Microsoft to patch, as the technique uses hardware to gain control of critical kernel structures. According to Microsoft, this technique involved hackers present on an already compromised system, it would not treat it as a security flaw.<\/p>\n<p><span style=\"color: green;\"><em>&#8220;The engineering team has finished their analysis of this report and determined that it requires the attacker already be running kernel code on the system. As such, this doesn\u2019t meet the bar for servicing in a security update however it may be addressed in a future version of Windows.<\/em><\/span><span style=\"color: green;\"><em>&#8221; \u00a0\u00a0<\/em><\/span><em>&#8211; Microsoft<\/em><\/p>\n<p>Microsoft has not yet discovered a patch for this, but told that they may address in a future version of Windows.<\/p>\n<p>If you require help, <a href=\"https:\/\/www.supportpro.com\/requestquote.php\">contact SupportPRO Server Admin<\/a><\/p>\n<p style=\"text-align: center;\"><!--HubSpot Call-to-Action Code --><span id=\"hs-cta-wrapper-9d590242-d641-4383-94b4-8cfd62f0af6b\" class=\"hs-cta-wrapper\"><span id=\"hs-cta-9d590242-d641-4383-94b4-8cfd62f0af6b\" class=\"hs-cta-node hs-cta-9d590242-d641-4383-94b4-8cfd62f0af6b\"><!-- [if lte IE 8]><\/p>\n\n\n\n\n\n<div id=\"hs-cta-ie-element\"><\/div>\n\n\n<![endif]--><a href=\"https:\/\/www.supportpro.com\/freecheckup.php\"><img decoding=\"async\" id=\"hs-cta-img-9d590242-d641-4383-94b4-8cfd62f0af6b\" class=\"hs-cta-img\" style=\"border-width: 0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/2725694\/9d590242-d641-4383-94b4-8cfd62f0af6b.png\" alt=\"Server not running properly? Get A FREE Server Checkup By Expert Server Admins - $125 Value\" \/><\/a><\/span><script charset=\"utf-8\" src=\"https:\/\/js.hscta.net\/cta\/current.js\"><\/script><script type=\"text\/javascript\"> hbspt.cta.load(2725694, '9d590242-d641-4383-94b4-8cfd62f0af6b', {}); <\/script><\/span><!-- end HubSpot Call-to-Action Code --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been&hellip;<\/p>\n","protected":false},"author":4,"featured_media":2110,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-2089","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-miscellaneous"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.9 - aioseo.com -->\n\t<meta name=\"description\" content=\"GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been designed to forbid the kernel of 64-bit versions of Windows operating systems from being patched, preventing attackers from executing malicious code or running rootkits at\" \/>\n\t<meta name=\"robots\" content=\"max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n\t<meta name=\"author\" content=\"SupportPRO Admin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.9\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Server Management Tips | SupportPRO Blog\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips\" \/>\n\t\t<meta property=\"og:description\" content=\"GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been designed to forbid the kernel of 64-bit versions of Windows operating systems from being patched, preventing attackers from executing malicious code or running rootkits at\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2017\/08\/ghosthook.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2017\/08\/ghosthook.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"680\" \/>\n\t\t<meta property=\"og:image:height\" content=\"400\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2017-08-29T07:12:48+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-29T11:23:50+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips\" \/>\n\t\t<meta name=\"twitter:description\" content=\"GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been designed to forbid the kernel of 64-bit versions of Windows operating systems from being patched, preventing attackers from executing malicious code or running rootkits at\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2017\/08\/ghosthook.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#article\",\"name\":\"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips\",\"headline\":\"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems\",\"author\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/managementadmin\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/wp-content\\\/uploads\\\/2017\\\/08\\\/ghosthook.png\",\"width\":680,\"height\":400},\"datePublished\":\"2017-08-29T01:12:48-06:00\",\"dateModified\":\"2019-10-29T05:23:50-06:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#webpage\"},\"articleSection\":\"Miscellaneous\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.supportpro.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/category\\\/miscellaneous\\\/#listItem\",\"name\":\"Miscellaneous\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/category\\\/miscellaneous\\\/#listItem\",\"position\":2,\"name\":\"Miscellaneous\",\"item\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/category\\\/miscellaneous\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#listItem\",\"name\":\"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#listItem\",\"position\":3,\"name\":\"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/category\\\/miscellaneous\\\/#listItem\",\"name\":\"Miscellaneous\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#organization\",\"name\":\"SupportPRO\",\"description\":\"SupportPRO Blog\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/\",\"telephone\":\"+18476076123\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/managementadmin\\\/#author\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/managementadmin\\\/\",\"name\":\"SupportPRO Admin\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/13d2f63048d631e03a432375448be5eb7861069df4fef10f0cb1c7b36554c225?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"SupportPRO Admin\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#webpage\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/\",\"name\":\"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips\",\"description\":\"GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been designed to forbid the kernel of 64-bit versions of Windows operating systems from being patched, preventing attackers from executing malicious code or running rootkits at\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/managementadmin\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/managementadmin\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/wp-content\\\/uploads\\\/2017\\\/08\\\/ghosthook.png\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#mainImage\",\"width\":680,\"height\":400},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\\\/#mainImage\"},\"datePublished\":\"2017-08-29T01:12:48-06:00\",\"dateModified\":\"2019-10-29T05:23:50-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/\",\"name\":\"Server Management Tips\",\"description\":\"SupportPRO Blog\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips<\/title>\n\n","aioseo_head_json":{"title":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips","description":"GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been designed to forbid the kernel of 64-bit versions of Windows operating systems from being patched, preventing attackers from executing malicious code or running rootkits at","canonical_url":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/","robots":"max-snippet:-1, max-image-preview:large, max-video-preview:-1","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#article","name":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips","headline":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems","author":{"@id":"https:\/\/www.supportpro.com\/blog\/author\/managementadmin\/#author"},"publisher":{"@id":"https:\/\/www.supportpro.com\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2017\/08\/ghosthook.png","width":680,"height":400},"datePublished":"2017-08-29T01:12:48-06:00","dateModified":"2019-10-29T05:23:50-06:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#webpage"},"isPartOf":{"@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#webpage"},"articleSection":"Miscellaneous"},{"@type":"BreadcrumbList","@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.supportpro.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/category\/miscellaneous\/#listItem","name":"Miscellaneous"}},{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/category\/miscellaneous\/#listItem","position":2,"name":"Miscellaneous","item":"https:\/\/www.supportpro.com\/blog\/category\/miscellaneous\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#listItem","name":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#listItem","position":3,"name":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems","previousItem":{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/category\/miscellaneous\/#listItem","name":"Miscellaneous"}}]},{"@type":"Organization","@id":"https:\/\/www.supportpro.com\/blog\/#organization","name":"SupportPRO","description":"SupportPRO Blog","url":"https:\/\/www.supportpro.com\/blog\/","telephone":"+18476076123"},{"@type":"Person","@id":"https:\/\/www.supportpro.com\/blog\/author\/managementadmin\/#author","url":"https:\/\/www.supportpro.com\/blog\/author\/managementadmin\/","name":"SupportPRO Admin","image":{"@type":"ImageObject","@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/13d2f63048d631e03a432375448be5eb7861069df4fef10f0cb1c7b36554c225?s=96&d=mm&r=g","width":96,"height":96,"caption":"SupportPRO Admin"}},{"@type":"WebPage","@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#webpage","url":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/","name":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips","description":"GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been designed to forbid the kernel of 64-bit versions of Windows operating systems from being patched, preventing attackers from executing malicious code or running rootkits at","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.supportpro.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#breadcrumblist"},"author":{"@id":"https:\/\/www.supportpro.com\/blog\/author\/managementadmin\/#author"},"creator":{"@id":"https:\/\/www.supportpro.com\/blog\/author\/managementadmin\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2017\/08\/ghosthook.png","@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#mainImage","width":680,"height":400},"primaryImageOfPage":{"@id":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/#mainImage"},"datePublished":"2017-08-29T01:12:48-06:00","dateModified":"2019-10-29T05:23:50-06:00"},{"@type":"WebSite","@id":"https:\/\/www.supportpro.com\/blog\/#website","url":"https:\/\/www.supportpro.com\/blog\/","name":"Server Management Tips","description":"SupportPRO Blog","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.supportpro.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Server Management Tips | SupportPRO Blog","og:type":"article","og:title":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips","og:description":"GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been designed to forbid the kernel of 64-bit versions of Windows operating systems from being patched, preventing attackers from executing malicious code or running rootkits at","og:url":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/","og:image":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2017\/08\/ghosthook.png","og:image:secure_url":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2017\/08\/ghosthook.png","og:image:width":680,"og:image:height":400,"article:published_time":"2017-08-29T07:12:48+00:00","article:modified_time":"2019-10-29T11:23:50+00:00","twitter:card":"summary","twitter:title":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems | Server Management Tips","twitter:description":"GhostHook is a new attack technique which allows hackers to bypass kernel protections of Windows 10 PatchGuard and plant rootkits within systems. PatchGuard is a software tool that has been designed to forbid the kernel of 64-bit versions of Windows operating systems from being patched, preventing attackers from executing malicious code or running rootkits at","twitter:image":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2017\/08\/ghosthook.png"},"aioseo_meta_data":{"post_id":"2089","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-06-17 13:32:12","breadcrumb_settings":null,"limit_modified_date":false,"open_ai":null,"ai":null,"created":"2021-12-10 16:10:46","updated":"2026-07-01 00:57:07"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.supportpro.com\/blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.supportpro.com\/blog\/category\/miscellaneous\/\" title=\"Miscellaneous\">Miscellaneous<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tGhostHook: A Kernel-Level Threat in 64-Bit Windows Systems\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.supportpro.com\/blog"},{"label":"Miscellaneous","link":"https:\/\/www.supportpro.com\/blog\/category\/miscellaneous\/"},{"label":"GhostHook: A Kernel-Level Threat in 64-Bit Windows Systems","link":"https:\/\/www.supportpro.com\/blog\/ghosthook-a-kernel-level-threat-in-64-bit-windows-systems\/"}],"_links":{"self":[{"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/posts\/2089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/comments?post=2089"}],"version-history":[{"count":13,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/posts\/2089\/revisions"}],"predecessor-version":[{"id":4375,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/posts\/2089\/revisions\/4375"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/media\/2110"}],"wp:attachment":[{"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/media?parent=2089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/categories?post=2089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/tags?post=2089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}