A forum for reverse engineering, OS internals and malware analysis 

All off-topic discussion goes here.
 #9706  by lorddoskias
 Tue Nov 15, 2011 11:53 am
I'd like to stir (if possible) a discussion about pros/cons of WDF driver model VS WDM for rootkits and antivirus drivers. From what I've seen and from personal experience (though I'm still a noob) WDM is good in that you have to do most of the stuff manually and at the same time you are given the right foundational elements so it is like building a lego. On the other hand I haven't seen any WDF mentioning in terms of a rootkit being written in WDF ? Is there any particular reason why WDF and more specifically KMDF (and why not UMDF even?) are not widely (at all?) used for development of rootkit/security type of software ?
 #9727  by EP_X0FF
 Thu Nov 17, 2011 11:30 am
Obviously because drivers with rootkit-alike components are not usual drivers.
Thread moved.