A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #10531  by novice
 Thu Dec 22, 2011 2:47 pm
Hello!

Can anybody give some introduction how hips systems can work from technical perspective?
I read on this forum that main av companies are making win32k.sys hooks. How it is achieved/can someone give an example of hooking win32k?
Thank you for any help.

mb
 #10538  by rkhunter
 Thu Dec 22, 2011 3:31 pm
You can run anti-rootkit on system with HIPS installed, for example, Rku or Xuetr and look on system modifications.
 #10541  by novice
 Thu Dec 22, 2011 3:38 pm
rkhuner,
Thank you. Well I would rather try to understand main mechanism of working hips systems, like is it preventing userland attacks or rather kernel or both?
BTW is there any good tutorial, or list of known usermode attacks? I mean how its realized how it is working etc?
Sorry, maybe my question seems to be stupid for you, but I'm new in this area, so I woul appreciate ANY links, tutorials and knowledge that you can give me..

THANK YOU!