POC about how to detect windows kernel debug by pool tag.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
gmh5225 223728a3b6
Update
2 years ago
images Update 2 years ago
.clang-format Update 2 years ago
LICENSE Update 2 years ago
README.md Update 2 years ago
detect.h Update 2 years ago
detect.poc.pooltag.cpp Update 2 years ago
main.cpp Update 2 years ago
poc.sln Update 2 years ago
poc.vcxproj Update 2 years ago
poc.vcxproj.filters Update 2 years ago
util.cpp Update 2 years ago
util.h Update 2 years ago

README.md

AntiKernelDebug-poc

What's this?

A POC about how to detect windows kernel debug by pool tag.

How does this poc actually work?

Query system pool tag information matches TagUlong == 'oIdK'.

Tested in Win10 1809

image