Catalogue of Kernel-mode Backdoors

Some time ago Skape and Skywing have published a Catalogue of Windows Kernel-mode Backdoor Techniques.
On 28 pages their whitepaper describes several means to get your code covertly executed in the kernel of Microsoft Windows. The document also provides good hints on how to detect these manipulations. Everyone who conducts forensic examinations on Windows memory dumps should be aware of these techniques.

Archives

Imprint

This blog is a project of:
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de

Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
Powered by Movable Type 5.12