-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Labels
usermodeChanges need to be made to the usermode codeChanges need to be made to the usermode code
Milestone
Description
NMIs can catch the driver execution code.
Since we (kdmapper) are currently mapping into unsigned memory, NMIs will be thrown and caught at which point the RIP register will be checked and we are caught! Due to this, we should do something like SinMapper does.
Potentially a custom mapper could be wrote for this project (likely using a publicly known vulnerable driver)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
usermodeChanges need to be made to the usermode codeChanges need to be made to the usermode code