Skip to main content
Sogen implements Windows Structured Exception Handling (SEH), allowing applications to catch and handle hardware and software exceptions. This is critical for running real-world Windows binaries that rely on exception handling for error recovery and control flow.

Exception Types

Windows exceptions fall into several categories:

Hardware Exceptions

  • Access Violation (STATUS_ACCESS_VIOLATION): Reading/writing unmapped or protected memory
  • Guard Page Violation (STATUS_GUARD_PAGE_VIOLATION): Accessing guard page (one-time exception)
  • Illegal Instruction (STATUS_ILLEGAL_INSTRUCTION): Invalid opcode
  • Integer Division by Zero (STATUS_INTEGER_DIVIDE_BY_ZERO): Division by zero
  • Single Step (STATUS_SINGLE_STEP): Debug trap flag set
  • Breakpoint (STATUS_BREAKPOINT): INT3 instruction

Software Exceptions

  • Raised Exception (NtRaiseException): Application-generated exception
  • Hard Error (NtRaiseHardError): Critical system error

Exception Record

Exceptions are represented by EXCEPTION_RECORD structures:
For access violations, ExceptionInformation contains:
  • [0]: Operation type (0=read, 1=write, 8=DEP violation)
  • [1]: Virtual address that caused the fault

Exception Dispatch Flow

Exception Dispatch Implementation

Triggering an Exception

From exception_dispatch.cpp:212:

Stack Layout

The exception dispatcher builds a specific stack layout:
Stack layout after exception dispatch:

Specific Exception Types

Access Violation

From exception_dispatch.cpp:256:
This is called from the memory subsystem when:
  • Reading unmapped memory
  • Writing read-only memory
  • Executing non-executable memory

Guard Page Violation

Guard pages are used for:
  • Stack growth detection: Automatically commit stack pages
  • Heap debugging: Detect buffer overruns
  • Copy-on-write: Implement lazy copying

Illegal Instruction

Caught by the CPU backend when encountering invalid opcodes.

Breakpoint

Triggered by INT3 instruction (opcode 0xCC), commonly used by debuggers.

Single Step

Called after each instruction when the trap flag (TF) in RFLAGS is set.

Debug Exceptions

Windows has special handling for INT 2Dh instructions used by debuggers: From exception_dispatch.cpp:157:

Exception Continuation

After handling an exception, applications can:
  1. Continue execution: Resume at the faulting instruction
  2. Continue search: Let the next handler try
  3. Unwind: Clean up and propagate exception
This is handled by the NtContinue syscall:

Raised Exceptions

Applications can manually raise exceptions:

WOW64 Exception Handling

For 32-bit processes running under WOW64, exception dispatch uses the “Heaven’s Gate” mechanism to transition between 32-bit and 64-bit mode:
This ensures exception handling works correctly for both 32-bit and 64-bit code.

Exception Callbacks

Sogen provides hooks for exception monitoring:
This enables:
  • Logging: Record exception types and locations
  • Analysis: Detect exception-based anti-analysis
  • Debugging: Break on specific exception types
  • Fuzzing: Track exception coverage

Next Steps