2020-07-21 19:29:59 +00:00
|
|
|
0000000000000000 f30f0128 RSTORSSP qword ptr [eax]
|
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_SS, Ins cat: CET, CET tracked: no
|
2020-07-21 08:19:18 +00:00
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: ecx, bit: 7
|
|
|
|
Valid modes
|
|
|
|
R0: yes, R1: yes, R2: yes, R3: yes
|
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: yes, SGX off: yes, TSX on: yes, TSX off: yes
|
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 0, Acc: RW, Type: Memory, Size: 8, RawSize: 8, Encoding: M, Shadow stack: 1,
|
2020-07-21 08:19:18 +00:00
|
|
|
Segment: 3, Base: 0,
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 1, Acc: RW, Type: Register, Size: 4, RawSize: 4, Encoding: S, RegType: SSP, RegSize: 4, RegId: 0, RegCount: 1
|
2020-07-21 08:19:18 +00:00
|
|
|
|
|
|
|
0000000000000004 f30f01ea SAVEPREVSSP
|
2020-07-21 19:29:59 +00:00
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_SS, Ins cat: CET, CET tracked: no
|
2020-07-21 08:19:18 +00:00
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: ecx, bit: 7
|
|
|
|
Valid modes
|
|
|
|
R0: yes, R1: yes, R2: yes, R3: yes
|
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: yes, SGX off: yes, TSX on: yes, TSX off: yes
|
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 0, Acc: RW, Type: Memory, Size: 12, RawSize: 12, Encoding: S, Shadow stack: 2,
|
2020-07-21 08:19:18 +00:00
|
|
|
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 1, Acc: R-, Type: Register, Size: 4, RawSize: 4, Encoding: S, RegType: SSP, RegSize: 4, RegId: 0, RegCount: 1
|
2020-07-21 08:19:18 +00:00
|
|
|
|
|
|
|
0000000000000008 f30f01e8 SETSSBSY
|
2020-07-21 19:29:59 +00:00
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_SS, Ins cat: CET, CET tracked: no
|
2020-07-21 08:19:18 +00:00
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: ecx, bit: 7
|
|
|
|
Valid modes
|
|
|
|
R0: yes, R1: yes, R2: yes, R3: yes
|
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: yes, SGX off: yes, TSX on: yes, TSX off: yes
|
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 0, Acc: RW, Type: Memory, Size: 8, RawSize: 8, Encoding: S, Shadow stack: 4,
|
|
|
|
|
|
|
|
Operand: 1, Acc: RW, Type: Register, Size: 4, RawSize: 4, Encoding: S, RegType: SSP, RegSize: 4, RegId: 0, RegCount: 1
|
2020-07-21 08:19:18 +00:00
|
|
|
|
|
|
|
000000000000000C f30f1ec8 RDSSPD eax
|
2020-07-21 19:29:59 +00:00
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_SS, Ins cat: CET, CET tracked: no
|
2020-07-21 08:19:18 +00:00
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: ecx, bit: 7
|
|
|
|
Valid modes
|
|
|
|
R0: yes, R1: yes, R2: yes, R3: yes
|
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: yes, SGX off: yes, TSX on: yes, TSX off: yes
|
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
|
|
|
Operand: 0, Acc: -W, Type: Register, Size: 4, RawSize: 4, Encoding: M, RegType: General Purpose, RegSize: 4, RegId: 0, RegCount: 1
|
|
|
|
Operand: 1, Acc: R-, Type: Register, Size: 4, RawSize: 4, Encoding: S, RegType: SSP, RegSize: 4, RegId: 0, RegCount: 1
|
|
|
|
|
2020-07-21 19:29:59 +00:00
|
|
|
0000000000000010 f30f1efa ENDBR64
|
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_IBT, Ins cat: CET, CET tracked: no
|
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: edx, bit: 20
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid modes
|
|
|
|
R0: yes, R1: yes, R2: yes, R3: yes
|
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: yes, SGX off: yes, TSX on: yes, TSX off: yes
|
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
|
|
|
|
2020-07-21 19:29:59 +00:00
|
|
|
0000000000000014 f30f1efb ENDBR32
|
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_IBT, Ins cat: CET, CET tracked: no
|
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: edx, bit: 20
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid modes
|
|
|
|
R0: yes, R1: yes, R2: yes, R3: yes
|
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: yes, SGX off: yes, TSX on: yes, TSX off: yes
|
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
|
|
|
|
2020-07-21 19:29:59 +00:00
|
|
|
0000000000000018 f30fae30 CLRSSBSY qword ptr [eax]
|
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_SS, Ins cat: CET, CET tracked: no
|
2020-07-21 08:19:18 +00:00
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: ecx, bit: 7
|
|
|
|
Valid modes
|
|
|
|
R0: yes, R1: yes, R2: yes, R3: yes
|
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: yes, SGX off: yes, TSX on: yes, TSX off: yes
|
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 0, Acc: RW, Type: Memory, Size: 8, RawSize: 8, Encoding: M, Shadow stack: 1,
|
2020-07-21 08:19:18 +00:00
|
|
|
Segment: 3, Base: 0,
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 1, Acc: RW, Type: Register, Size: 4, RawSize: 4, Encoding: S, RegType: SSP, RegSize: 4, RegId: 0, RegCount: 1
|
2020-07-21 08:19:18 +00:00
|
|
|
|
2020-07-21 19:29:59 +00:00
|
|
|
000000000000001C f30faee8 INCSSPD eax
|
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_SS, Ins cat: CET, CET tracked: no
|
2020-07-21 08:19:18 +00:00
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: ecx, bit: 7
|
|
|
|
Valid modes
|
|
|
|
R0: yes, R1: yes, R2: yes, R3: yes
|
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: yes, SGX off: yes, TSX on: yes, TSX off: yes
|
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 0, Acc: R-, Type: Register, Size: 4, RawSize: 4, Encoding: M, RegType: General Purpose, RegSize: 4, RegId: 0, RegCount: 1
|
|
|
|
Operand: 1, Acc: R-, Type: Memory, Size: 8, RawSize: 8, Encoding: S, Shadow stack: 2,
|
|
|
|
|
|
|
|
Operand: 2, Acc: RW, Type: Register, Size: 4, RawSize: 4, Encoding: S, RegType: SSP, RegSize: 4, RegId: 0, RegCount: 1
|
2020-07-21 08:19:18 +00:00
|
|
|
|
2020-07-21 19:29:59 +00:00
|
|
|
0000000000000020 660f38f500 WRUSSD dword ptr [eax], eax
|
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_SS, Ins cat: CET, CET tracked: no
|
2020-07-21 08:19:18 +00:00
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: ecx, bit: 7
|
|
|
|
Valid modes
|
2022-01-05 12:03:13 +00:00
|
|
|
R0: yes, R1: no, R2: no, R3: no
|
2020-07-21 08:19:18 +00:00
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2022-01-05 12:03:13 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: no, SGX off: yes, TSX on: yes, TSX off: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 0, Acc: -W, Type: Memory, Size: 4, RawSize: 4, Encoding: M, Shadow stack: 1,
|
2020-07-21 08:19:18 +00:00
|
|
|
Segment: 3, Base: 0,
|
|
|
|
Operand: 1, Acc: R-, Type: Register, Size: 4, RawSize: 4, Encoding: R, RegType: General Purpose, RegSize: 4, RegId: 0, RegCount: 1
|
|
|
|
|
2020-07-21 19:29:59 +00:00
|
|
|
0000000000000025 0f38f600 WRSSD dword ptr [eax], eax
|
|
|
|
DSIZE: 32, ASIZE: 32, VLEN: -
|
2020-07-22 06:15:29 +00:00
|
|
|
ISA Set: CET_SS, Ins cat: CET, CET tracked: no
|
2020-07-21 08:19:18 +00:00
|
|
|
CPUID leaf: 0x00000007, sub-leaf: 0x00000000, reg: ecx, bit: 7
|
|
|
|
Valid modes
|
|
|
|
R0: yes, R1: yes, R2: yes, R3: yes
|
|
|
|
Real: yes, V8086: yes, Prot: yes, Compat: yes, Long: yes
|
2020-09-10 08:06:20 +00:00
|
|
|
SMM on: yes, SMM off: yes, SGX on: yes, SGX off: yes, TSX on: yes, TSX off: yes
|
|
|
|
VMXRoot: yes, VMXNonRoot: yes, VMXRoot SEAM: yes, VMXNonRoot SEAM: yes, VMX off: yes
|
2020-07-21 08:19:18 +00:00
|
|
|
Valid prefixes
|
|
|
|
REP: no, REPcc: no, LOCK: no
|
|
|
|
HLE: no, XACQUIRE only: no, XRELEASE only: no
|
|
|
|
BND: no, BHINT: no, DNT: no
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 0, Acc: -W, Type: Memory, Size: 4, RawSize: 4, Encoding: M, Shadow stack: 1,
|
2020-07-21 08:19:18 +00:00
|
|
|
Segment: 3, Base: 0,
|
2020-07-21 19:29:59 +00:00
|
|
|
Operand: 1, Acc: R-, Type: Register, Size: 4, RawSize: 4, Encoding: R, RegType: General Purpose, RegSize: 4, RegId: 0, RegCount: 1
|
2020-07-21 08:19:18 +00:00
|
|
|
|