The Payload Podcast #002 with Connor McGarr

The Payload Podcast #002 with Connor McGarr

Source: YouTube · John Hammond · published Feb 20, 2026 · 1:12:26

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The episode explores modern Windows security architecture, detailing the shift to hypervisor-enforced isolation via Virtual Trust Levels (VTLs) and ARM-specific mitigations like Pointer Authentication (PAC) to counter kernel-level threats.

Key Takeaways:
• Windows security now relies on Hyper-V to isolate the "Secure Kernel" in VTL1, preventing kernel-mode attackers from bypassing memory integrity checks 15:00-16:00.
• ARM64 utilizes Pointer Authentication (PAC) to sign pointers, protecting return addresses from stack overflow exploits in the absence of x64 Shadow Stacks 41:00-42:00.
• WinDbg queries reveal unique PAC keys per process and mitigation flags, highlighting the complexity of validating modern exploit protections 55:00-56:00.
• The Secure Kernel manages system call handlers and protects MSRs via intercepts, effectively neutralizing rootkit techniques that attempt to corrupt system registers 36:00-37:00.
• Reverse engineering ARM Windows presents challenges due to a lack of public documentation compared to x86/x64 architectures 49:00-50:00.

This discussion highlights the increasing complexity of low-level Windows security and the necessity for researchers to understand hypervisor-enforced boundaries.

Sources:

  • 15:00 Overview of the new virtualized Windows security model
  • 24:00 Diagram of VTL0 and VTL1 isolation
  • 41:00 Explanation of ARM Pointer Authentication (PAC)
  • 55:00 WinDbg demonstration of process mitigation flags and PAC keys

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

it. I clicked the button. Fingers crossed. He haha. >> Now we're supposed to roast Connor about having nothing on his walls. [laughter] >> I moved where my office was in the house. So it's bare bones right now. Yeah. >> It is a completely blank white wall. >> It's as generic as you could get possibly. Yes. >> Half insane asylum kind of thing. Like [laughter] >> Yeah. Mine mine isn't even mine. This is my fiance's. And there's like this weird big trophy in the background. >> Looks good though. >> Yeah. But I Yeah, but I don't want people to think it's like from pee-wee, you know, te-ball or something when I was a kid that I'm just still storing in the back end. [laughter] >> It's your little league trophy. For sure. For sure. >> Yeah. Yeah. Exactly. Everyone's a winner. Everyone's a winner.…