Hi,
some probably already know, but Cr4sh posted in russian blog of esagelab about how to bypass detection of hidden executable code in a nifty way. So all credit for PoC goes to him.
Original: http://esagelab.ru/blog/tech/%D0%BE%D0% ... B#more-130
English version: http://translate.google.com/translate?h ... BB&prev=_t
Repository: https://github.com/Cr4sh/DrvHide-PoC
BTW
allive -> alive
Regards
some probably already know, but Cr4sh posted in russian blog of esagelab about how to bypass detection of hidden executable code in a nifty way. So all credit for PoC goes to him.
Original: http://esagelab.ru/blog/tech/%D0%BE%D0% ... B#more-130
English version: http://translate.google.com/translate?h ... BB&prev=_t
Repository: https://github.com/Cr4sh/DrvHide-PoC
BTW
allive -> alive
Regards