A forum for reverse engineering, OS internals and malware analysis 

Forum for discussion about kernel-mode development.
 #24442  by AaLl86
 Thu Nov 27, 2014 12:04 pm
Hi All!
According to my previous talks in the EP_X0FF AntiDse project, I would like to signal here some articles on my work on the Kernel Patch Protection of Windows 8.1

I have completed a presentation at NoSuchCon conference in Paris. My objective was to demonstate that with the Patchguard 8.1 Code, you can do a lot of great things.... Here is the link:
http://www.nosuchcon.org/talks/2014/D2_ ... ctions.pdf

The introductive blog post is the following one:
http://vrt-blog.snort.org/2014/08/the-w ... ction.html

For all those interested, even Tandasat and other 2 guys from Positive Research, has done a great work:
https://github.com/tandasat/PgResarch/tree/master/DisPG
http://blog.ptsecurity.com/2014/09/micr ... patch.html

Hope that this could be helpful for someone.

Cheers,
Andrea
 #24470  by TurlaBoy
 Sun Nov 30, 2014 1:22 pm
Hey Andrea,

Nice job, have you done some research you'd like to share about windows 10 PG?
 #24474  by Vrtule
 Sun Nov 30, 2014 8:51 pm
Hello Andrea,

thanks for sharing this. Its a nice read. Unfortunately, I cannot find any information about what exactly the Patchguard protects on newer versions of Windows (Windows 8+ especially). I am interested mainly in protected data structures (processes, driver objects etc.).
Hey Andrea,

Nice job, have you done some research you'd like to share about windows 10 PG?
I think it would be better to wait until Windows 10 reaches their stable form (for example a RTM build) and do a detailed analysis then.
 #24486  by TurlaBoy
 Mon Dec 01, 2014 11:04 am
Vrtule wrote:Hello Andrea,

thanks for sharing this. Its a nice read. Unfortunately, I cannot find any information about what exactly the Patchguard protects on newer versions of Windows (Windows 8+ especially). I am interested mainly in protected data structures (processes, driver objects etc.).
Hey Andrea,

Nice job, have you done some research you'd like to share about windows 10 PG?
I think it would be better to wait until Windows 10 reaches their stable form (for example a RTM build) and do a detailed analysis then.
That's truth, Another thing I'd like to know is if/what changed in PG since skywing joined MS sec l33t team
 #24489  by m5home
 Mon Dec 01, 2014 12:54 pm
Thanks for sharing! :D