INTEL_REPORT
Google Project Zero · published 2/25/2026, 11:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
A Deep Dive into the GetProcessHandleFromHwnd API In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I thought I should take a closer look. I typically start by reading the documentation for an API I don’t know about, assuming it’s documented at all. It can give you an idea of how long the API has…
https://projectzero.google/2026/02/gphfh-deep-dive.html
sha256:37b293fcc2af67b5ef2212f19bd0316bdf45f61656a2f65c4c0944b13944446e
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| process.you |
| Open → |
| cve | CVE-2023-41772 | Open → |