[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRC6xkjeXbIu9kkdU-G1xrcpgb8iRoZujy1T3Gk_fH3g":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1191,"What are the three methods discussed in the article for triggering a BSOD by terminating a process?","The article discusses three methods: calling `RtlSetProcessIsCritical` to mark the current process as critical, using `NtSetInformationProcess` with `ProcessBreakOnTermination` (class 29) to set a process as critical, and calling `NtRaiseHardError` with specific parameters (e.g., `0xC0000217`, `OptionShutdownSystem`, `ResponseYes`) to force a system shutdown. Each causes a Blue Screen of Death when the critical process exits, as detailed in the [Analysis of Exploitation Techniques for Triggering BSOD by Terminating Processes](\u002Fnews\u002Fanalysis-of-exploitation-techniques-for-triggering-bsod-by-terminating-processes).","\u003Cp>The article discusses three methods: calling `RtlSetProcessIsCritical` to mark the current process as critical, using `NtSetInformationProcess` with `ProcessBreakOnTermination` (class 29) to set a process as critical, and calling `NtRaiseHardError` with specific parameters (e.g., `0xC0000217`, `OptionShutdownSystem`, `ResponseYes`) to force a system shutdown. Each causes a Blue Screen of Death when the critical process exits, as detailed in the [Analysis of Exploitation Techniques for Triggering BSOD by Terminating Processes](\u002Fnews\u002Fanalysis-of-exploitation-techniques-for-triggering-bsod-by-terminating-processes).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fanalysis-of-exploitation-techniques-for-triggering-bsod-by-terminating-processes\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-three-methods-discussed-in-the-article-for-triggering-a-bsod-by-ter-1777480061949","BSOD, RtlSetProcessIsCritical, NtSetInformationProcess, NtRaiseHardError, ProcessBreakOnTermination, critical process, privilege escalation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},289,"Analysis of Exploitation Techniques for Triggering BSOD by Terminating Processes","analysis-of-exploitation-techniques-for-triggering-bsod-by-terminating-processes","Learn how to trigger BSOD by terminating critical processes using RtlSetProcessIsCritical, NtSetInformationProcess, and NtRaiseHardError. Includes defense strategies.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>BSOD, short for Blue Screen of Death, refers to the system crash screen.\u003C\u002Fp>\u003Cp>It is typically caused by errors in Ring0-level kernel programs and is frequently encountered in privilege escalation vulnerabilities.\u003C\u002Fp>\u003Cp>During penetration testing, certain scenarios require system reboots, such as configuring Password Filter DLL, enabling Wdigest authentication, or restarting domain controller servers.\u003C\u002Fp>\u003Cp>Under specific conditions, triggering a BSOD can be chosen to force a system restart.\u003C\u002Fp>\u003Cp>So, is there a reliable method to trigger a BSOD? What are further exploitation ideas? How can it be defended against?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Testing several methods to trigger BSOD by terminating the current process\u003C\u002Fli>\u003Cli>Modifying a specified process to cause BSOD upon its termination\u003C\u002Fli>\u003Cli>How to defend against such attacks\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods to Trigger BSOD by Terminating the Current Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Found the following reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.csdn.net\u002Fqq125096885\u002Farticle\u002Fdetails\u002F52911870\u003C\u002Fp>\u003Cp>Provides multiple methods to cause a BSOD by terminating the current process\u003C\u002Fp>\u003Cp>After testing, the methods applicable to the Win7 system are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>CallRtlSetProcessIsCritical\u003C\u002Fli>\u003Cli>CallNtSetInformationThread\u003C\u002Fli>\u003Cli>CallNtRaiseHardError\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. CallRtlSetProcessIsCritical\u003C\u002Fh3>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>RtlSetProcessIsCritical(TRUE, NULL, FALSE);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F43405\u002FProtecting-Your-Process-with-RtlSetProcessIsCriti\u003C\u002Fp>\u003Cp>Function prototype:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NTSTATUS\u003Cbr>RtlSetProcessIsCritical (\u003Cbr>    BOOLEAN bNew,    \t\u002F\u002F new setting for process\u003Cbr>    BOOLEAN *pbOld,    \t\u002F\u002F pointer which receives old setting (can be null)\u003Cbr>    BOOLEAN bNeedScb);    \t\u002F\u002F need system critical breaks\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The first parameter, when set to TRUE, marks the current process as a critical process; when set to FALSE, the current process is not a critical process\u003C\u002Fp>\u003Ch4>critical process:\u003C\u002Fh4>\u003Cp>Specific to system processes, known system processes that are critical include:\u003C\u002Fp>\u003Cul>\u003Cli>csrss.exe\u003C\u002Fli>\u003Cli>lsass.exe\u003C\u002Fli>\u003Cli>services.exe\u003C\u002Fli>\u003Cli>smss.exe\u003C\u002Fli>\u003Cli>svchost.exe\u003C\u002Fli>\u003Cli>wininit.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>When a critical process exits, it causes a system BSOD, so if we also set the current process as a critical process, it will similarly cause a BSOD upon process exit\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016708065_0_561c2c124f.jpeg\">\u003C\u002Fp>\u003Ch3>2. NtSetInformationProcess\u003C\u002Fh3>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ULONG A = 1;\u003Cbr>NtSetInformationProcess(GetCurrentProcess(), ProcessBreakOnTermination, &amp;A, sizeof(ULONG));\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fundocumented.ntinternals.net\u002Findex.html?page=UserMode%2FUndocumented%20Functions%2FNT%20Objects%2FProcess%2FNtSetInformationProcess.html\u003C\u002Fp>\u003Cp>Function prototype:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NtSetInformationProcess(\u003Cbr>\u003Cbr>  IN HANDLE               ProcessHandle,\u003Cbr>  IN PROCESS_INFORMATION_CLASS ProcessInformationClass,\u003Cbr>  IN PVOID                ProcessInformation,\u003Cbr>  IN ULONG                ProcessInformationLength );\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The first parameter represents the process handle\u003C\u002Fp>\u003Cp>The second parameter ProcessInformationClass, I found a reference in the description of NtQueryInformationProcess, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002Fapi\u002Fwinternl\u002Fnf-winternl-ntqueryinformationprocess\u003C\u002Fp>\u003Cp>ProcessBreakOnTermination: 29, Retrieves a ULONG value indicating whether the process is considered critical.\u003C\u002Fp>\u003Cp>Therefore, set ProcessInformationClass to 29\u003C\u002Fp>\u003Cp>The third parameter, ProcessInformation, when set to TRUE, marks the current process as a critical process; when set to FALSE, the current process is not a critical process\u003C\u002Fp>\u003Cp>The fourth parameter is the length, i.e., sizeof(ULONG)\u003C\u002Fp>\u003Ch3>3. CallNtRaiseHardError\u003C\u002Fh3>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef enum _HARDERROR_RESPONSE_OPTION {\u003Cbr>\tOptionAbortRetryIgnore,\u003Cbr>\tOptionOk,\u003Cbr>\tOptionOkCancel,\u003Cbr>\tOptionRetryCancel,\u003Cbr>\tOptionYesNo,\u003Cbr>\tOptionYesNoCancel,\u003Cbr>\tOptionShutdownSystem\u003Cbr>} HARDERROR_RESPONSE_OPTION, *PHARDERROR_RESPONSE_OPTION;\u003Cbr>\u003Cbr>typedef enum _HARDERROR_RESPONSE {\u003Cbr>\tResponseReturnToCaller,\u003Cbr>\tResponseNotHandled,\u003Cbr>\tResponseAbort,\u003Cbr>\tResponseCancel,\u003Cbr>\tResponseIgnore,\u003Cbr>\tResponseNo,\u003Cbr>\tResponseOk,\u003Cbr>\tResponseRetry,\u003Cbr>\tResponseYes\u003Cbr>} HARDERROR_RESPONSE, *PHARDERROR_RESPONSE;\u003Cbr>\u003Cbr>HARDERROR_RESPONSE OR;\u003Cbr>HARDERROR_RESPONSE_OPTION OP;\u003Cbr>OR = ResponseYes;\u003Cbr>OP = OptionShutdownSystem;\u003Cbr>NtRaiseHardError(0xC0000217, 0, 0, 0, OptionShutdownSystem, &amp;OR);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fundocumented.ntinternals.net\u002Findex.html?page=UserMode%2FUndocumented%20Functions%2FError%2FNtRaiseHardError.html\u003C\u002Fp>\u003Cp>Function prototype:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NtRaiseHardError(\u003Cbr>\u003Cbr>  IN NTSTATUS             ErrorStatus,\u003Cbr>  IN ULONG                NumberOfParameters,\u003Cbr>  IN PUNICODE_STRING      UnicodeStringParameterMask OPTIONAL,\u003Cbr>  IN PVOID                *Parameters,\u003Cbr>  IN HARDERROR_RESPONSE_OPTION ResponseOption,\u003Cbr>  OUT PHARDERROR_RESPONSE Response );\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This function is used to generate an application error dialog when handling exceptions. The typical usage is to pop up a dialog asking the user whether to terminate the process. However, if we set the parameters to 0xC0000217, OptionShutdownSystem, and ResponseYes, it will cause a BSOD with error code 0xC0000217.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016715624_1_bd9fc9c0b3.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>ErrorStatus can also be other values. Refer to the NTSTATUS description at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc704588.aspx\u003C\u002Fp>\u003Cp>Simply choose values representing failure functions, such as 0xC000000C(STATUS_TIMER_NOT_CANCELED), 0xC0000216(STATUS_NOT_SERVER_SESSION), 0xC0000219(STATUS_DEBUG_ATTACH_FAILED)\u003C\u002Fp>\u003Ch2>0x03 Method to cause BSOD by terminating a specified process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Among the three functions above, only NtSetInformationProcess supports passing a process handle\u003C\u002Fp>\u003Cp>Next, as long as we can obtain the handle of the specified process and pass it to NtSetInformationProcess, we can achieve terminating the specified process to cause BSOD\u003C\u002Fp>\u003Cp>The approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Elevate to Debug privilege\u003C\u002Fli>\u003Cli>Open the specified process via OpenProcess to obtain the process handle\u003C\u002Fli>\u003Cli>Call CallNtSetInformationProcess to set the specified process as a critical process\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Refer to the following link for the complete code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code also supports reverting a specified process from critical process to normal process\u003C\u002Fp>\u003Ch2>0x04 Defense Strategy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To avoid this situation, when terminating a process, we first need to check whether the process is a critical process. If it is a critical process, it must be set to a normal process before termination.\u003C\u002Fp>\u003Cp>This involves checking whether the process is a critical process.\u003C\u002Fp>\u003Cp>The kernel API NtQueryInformationProcess must be used to query ProcessBreakOnTermination and obtain process information.\u003C\u002Fp>\u003Cp>The key code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>status = NtQueryInformationProcess(hProcess, ProcessBreakOnTermination, &amp;breakOnTermination, sizeof(ULONG), NULL);\u003Cbr>if(status&lt;0)\u003Cbr>\tprintf(\"[!]NtQueryInformationProcess error\\n\");\u003Cbr>if(breakOnTermination ==1)\u003Cbr>\tprintf(\"[+]The process is critical\");\u003Cbr>else\u003Cbr>\tprintf(\"[!]The process is not critical\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For the complete code, please refer to the following link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements querying whether a specified process is a critical process\u003C\u002Fp>\u003Cp>In practical applications, it typically queries all processes in the current system to check for the existence of critical processes\u003C\u002Fp>\u003Cp>In code implementation, one can enumerate all process PIDs via EnumProcesses and then perform further queries\u003C\u002Fp>\u003Cp>Complete code can be referenced at the following link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements querying all processes in the current system, filtering out system processes, and marking critical processes\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested three methods to cause a BSOD by terminating the current process, further introduced methods to cause a BSOD by terminating specified processes, combined exploitation ideas, analyzed defense methods, and developed a program that queries all processes in the current system and marks critical processes, allowing them to be set as normal processes before termination to avoid system BSOD\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>BSOD, short for Blue Screen of Death, refers to the system crash screen.\u003C\u002Fp>\u003Cp>It is typically caused by errors in Ring0-level kernel programs and is frequently encountered in privilege escalation vulnerabilities.\u003C\u002Fp>\u003Cp>During penetration testing, certain scenarios require system reboots, such as configuring Password Filter DLL, enabling Wdigest authentication, or restarting domain controller servers.\u003C\u002Fp>\u003Cp>Under specific conditions, triggering a BSOD can be chosen to force a system restart.\u003C\u002Fp>\u003Cp>So, is there a reliable method to trigger a BSOD? What are further exploitation ideas? How can it be defended against?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Testing several methods to trigger BSOD by terminating the current process\u003C\u002Fli>\u003Cli>Modifying a specified process to cause BSOD upon its termination\u003C\u002Fli>\u003Cli>How to defend against such attacks\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods to Trigger BSOD by Terminating the Current Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Found the following reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.csdn.net\u002Fqq125096885\u002Farticle\u002Fdetails\u002F52911870\u003C\u002Fp>\u003Cp>Provides multiple methods to cause a BSOD by terminating the current process\u003C\u002Fp>\u003Cp>After testing, the methods applicable to the Win7 system are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>CallRtlSetProcessIsCritical\u003C\u002Fli>\u003Cli>CallNtSetInformationThread\u003C\u002Fli>\u003Cli>CallNtRaiseHardError\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>1. CallRtlSetProcessIsCritical\u003C\u002Fh3>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>RtlSetProcessIsCritical(TRUE, NULL, FALSE);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.codeproject.com\u002FArticles\u002F43405\u002FProtecting-Your-Process-with-RtlSetProcessIsCriti\u003C\u002Fp>\u003Cp>Function prototype:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NTSTATUS\u003Cbr>RtlSetProcessIsCritical (\u003Cbr>    BOOLEAN bNew,    \t\u002F\u002F new setting for process\u003Cbr>    BOOLEAN *pbOld,    \t\u002F\u002F pointer which receives old setting (can be null)\u003Cbr>    BOOLEAN bNeedScb);    \t\u002F\u002F need system critical breaks\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The first parameter, when set to TRUE, marks the current process as a critical process; when set to FALSE, the current process is not a critical process\u003C\u002Fp>\u003Ch4>critical process:\u003C\u002Fh4>\u003Cp>Specific to system processes, known system processes that are critical include:\u003C\u002Fp>\u003Cul>\u003Cli>csrss.exe\u003C\u002Fli>\u003Cli>lsass.exe\u003C\u002Fli>\u003Cli>services.exe\u003C\u002Fli>\u003Cli>smss.exe\u003C\u002Fli>\u003Cli>svchost.exe\u003C\u002Fli>\u003Cli>wininit.exe\u003C\u002Fli>\u003C\u002Ful>\u003Cp>When a critical process exits, it causes a system BSOD, so if we also set the current process as a critical process, it will similarly cause a BSOD upon process exit\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016708065_0_561c2c124f-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. NtSetInformationProcess\u003C\u002Fh3>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ULONG A = 1;\u003Cbr>NtSetInformationProcess(GetCurrentProcess(), ProcessBreakOnTermination, &amp;A, sizeof(ULONG));\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fundocumented.ntinternals.net\u002Findex.html?page=UserMode%2FUndocumented%20Functions%2FNT%20Objects%2FProcess%2FNtSetInformationProcess.html\u003C\u002Fp>\u003Cp>Function prototype:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NtSetInformationProcess(\u003Cbr>\u003Cbr>  IN HANDLE               ProcessHandle,\u003Cbr>  IN PROCESS_INFORMATION_CLASS ProcessInformationClass,\u003Cbr>  IN PVOID                ProcessInformation,\u003Cbr>  IN ULONG                ProcessInformationLength );\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The first parameter represents the process handle\u003C\u002Fp>\u003Cp>The second parameter ProcessInformationClass, I found a reference in the description of NtQueryInformationProcess, the address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fdesktop\u002Fapi\u002Fwinternl\u002Fnf-winternl-ntqueryinformationprocess\u003C\u002Fp>\u003Cp>ProcessBreakOnTermination: 29, Retrieves a ULONG value indicating whether the process is considered critical.\u003C\u002Fp>\u003Cp>Therefore, set ProcessInformationClass to 29\u003C\u002Fp>\u003Cp>The third parameter, ProcessInformation, when set to TRUE, marks the current process as a critical process; when set to FALSE, the current process is not a critical process\u003C\u002Fp>\u003Cp>The fourth parameter is the length, i.e., sizeof(ULONG)\u003C\u002Fp>\u003Ch3>3. CallNtRaiseHardError\u003C\u002Fh3>\u003Cp>Key code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>typedef enum _HARDERROR_RESPONSE_OPTION {\u003Cbr>\tOptionAbortRetryIgnore,\u003Cbr>\tOptionOk,\u003Cbr>\tOptionOkCancel,\u003Cbr>\tOptionRetryCancel,\u003Cbr>\tOptionYesNo,\u003Cbr>\tOptionYesNoCancel,\u003Cbr>\tOptionShutdownSystem\u003Cbr>} HARDERROR_RESPONSE_OPTION, *PHARDERROR_RESPONSE_OPTION;\u003Cbr>\u003Cbr>typedef enum _HARDERROR_RESPONSE {\u003Cbr>\tResponseReturnToCaller,\u003Cbr>\tResponseNotHandled,\u003Cbr>\tResponseAbort,\u003Cbr>\tResponseCancel,\u003Cbr>\tResponseIgnore,\u003Cbr>\tResponseNo,\u003Cbr>\tResponseOk,\u003Cbr>\tResponseRetry,\u003Cbr>\tResponseYes\u003Cbr>} HARDERROR_RESPONSE, *PHARDERROR_RESPONSE;\u003Cbr>\u003Cbr>HARDERROR_RESPONSE OR;\u003Cbr>HARDERROR_RESPONSE_OPTION OP;\u003Cbr>OR = ResponseYes;\u003Cbr>OP = OptionShutdownSystem;\u003Cbr>NtRaiseHardError(0xC0000217, 0, 0, 0, OptionShutdownSystem, &amp;OR);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fundocumented.ntinternals.net\u002Findex.html?page=UserMode%2FUndocumented%20Functions%2FError%2FNtRaiseHardError.html\u003C\u002Fp>\u003Cp>Function prototype:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>NtRaiseHardError(\u003Cbr>\u003Cbr>  IN NTSTATUS             ErrorStatus,\u003Cbr>  IN ULONG                NumberOfParameters,\u003Cbr>  IN PUNICODE_STRING      UnicodeStringParameterMask OPTIONAL,\u003Cbr>  IN PVOID                *Parameters,\u003Cbr>  IN HARDERROR_RESPONSE_OPTION ResponseOption,\u003Cbr>  OUT PHARDERROR_RESPONSE Response );\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This function is used to generate an application error dialog when handling exceptions. The typical usage is to pop up a dialog asking the user whether to terminate the process. However, if we set the parameters to 0xC0000217, OptionShutdownSystem, and ResponseYes, it will cause a BSOD with error code 0xC0000217.\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016715624_1_bd9fc9c0b3-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>ErrorStatus can also be other values. Refer to the NTSTATUS description at the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc704588.aspx\u003C\u002Fp>\u003Cp>Simply choose values representing failure functions, such as 0xC000000C(STATUS_TIMER_NOT_CANCELED), 0xC0000216(STATUS_NOT_SERVER_SESSION), 0xC0000219(STATUS_DEBUG_ATTACH_FAILED)\u003C\u002Fp>\u003Ch2>0x03 Method to cause BSOD by terminating a specified process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Among the three functions above, only NtSetInformationProcess supports passing a process handle\u003C\u002Fp>\u003Cp>Next, as long as we can obtain the handle of the specified process and pass it to NtSetInformationProcess, we can achieve terminating the specified process to cause BSOD\u003C\u002Fp>\u003Cp>The approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Elevate to Debug privilege\u003C\u002Fli>\u003Cli>Open the specified process via OpenProcess to obtain the process handle\u003C\u002Fli>\u003Cli>Call CallNtSetInformationProcess to set the specified process as a critical process\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Refer to the following link for the complete code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code also supports reverting a specified process from critical process to normal process\u003C\u002Fp>\u003Ch2>0x04 Defense Strategy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To avoid this situation, when terminating a process, we first need to check whether the process is a critical process. If it is a critical process, it must be set to a normal process before termination.\u003C\u002Fp>\u003Cp>This involves checking whether the process is a critical process.\u003C\u002Fp>\u003Cp>The kernel API NtQueryInformationProcess must be used to query ProcessBreakOnTermination and obtain process information.\u003C\u002Fp>\u003Cp>The key code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>status = NtQueryInformationProcess(hProcess, ProcessBreakOnTermination, &amp;breakOnTermination, sizeof(ULONG), NULL);\u003Cbr>if(status&lt;0)\u003Cbr>\tprintf(\"[!]NtQueryInformationProcess error\\n\");\u003Cbr>if(breakOnTermination ==1)\u003Cbr>\tprintf(\"[+]The process is critical\");\u003Cbr>else\u003Cbr>\tprintf(\"[!]The process is not critical\");\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For the complete code, please refer to the following link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements querying whether a specified process is a critical process\u003C\u002Fp>\u003Cp>In practical applications, it typically queries all processes in the current system to check for the existence of critical processes\u003C\u002Fp>\u003Cp>In code implementation, one can enumerate all process PIDs via EnumProcesses and then perform further queries\u003C\u002Fp>\u003Cp>Complete code can be referenced at the following link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements querying all processes in the current system, filtering out system processes, and marking critical processes\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article tested three methods to cause a BSOD by terminating the current process, further introduced methods to cause a BSOD by terminating specified processes, combined exploitation ideas, analyzed defense methods, and developed a program that queries all processes in the current system and marks critical processes, allowing them to be set as normal processes before termination to avoid system BSOD\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",29,"Onedaysec",4,"published","2026-02-02T07:25:19.684Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Trigger BSOD: Exploit Techniques for System Restart & Defense","BSOD exploitation, process termination, critical process, NtSetInformationProcess, RtlSetProcessIsCritical, NtRaiseHardError, Windows security, system crash, penetration testing, privilege escalation",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],1194,1193,1192,{"title":39,"description":39,"image":39},"2026-07-24T15:37:08.975Z","2026-07-23T16:02:39.551Z","draft","2026-07-23T16:17:18.436Z"]