Executable Secrets: How DreamWalker Builds Trustworthy Call Stacks episode artwork

EPISODE · Jul 31, 2025 · 15 MIN

Executable Secrets: How DreamWalker Builds Trustworthy Call Stacks

from Decoded: The Cybersecurity Podcast · host Edward Henriquez

The MaxDcb Blog discusses DreamWalkers, a novel shellcode loader that creates clean and believable call stacks, even for reflectively loaded modules. The author was inspired by Donut and MemoryModule to build a position-independent shellcode loader, implementing features like command-line argument passing and a unique approach to .NET (CLR) payload support using an intermediate DLL. The core innovation of DreamWalkers lies in its ability to restore proper stack unwinding by manually registering unwind information via RtlAddFunctionTable, a technique that allows reflectively loaded code to blend in more effectively with legitimate processes, even when subjected to scrutiny by EDR and debugging tools. This method, combined with module stomping, significantly enhances the stealth of the shellcode.

Episode metadata supplied by the publisher feed · Published Jul 31, 2025

Embed this episode

NOW PLAYING

Executable Secrets: How DreamWalker Builds Trustworthy Call Stacks

0:00 15:08

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Decoded: The Cybersecurity Podcast?

This episode is 15 minutes long.

When was this Decoded: The Cybersecurity Podcast episode published?

This episode was published on July 31, 2025.

Can I download this Decoded: The Cybersecurity Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!