Memory analysis

Catalogue of Kernel-mode Backdoors

Some time ago Skape and Skywing have published a Catalogue of Windows Kernel-mode Backdoor Techniques.

On 28 pages their whitepaper describes several means to get your code covertly executed in the kernel of Microsoft Windows. The document also provides good hints on how to detect these manipulations. Everyone who conducts forensic examinations on Windows memory dumps should be aware of these techniques.

Deutsch

Deutschsprachige Ausgabe

Categories

Subscribe

Imprint

This blog is a project of
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
Germany
impressum@forensikblog.de

Copyright © 2005-2010 by
Andreas Schuster
All rights reserved.