Hi,
I published an article concerning a driver signing policy bypass there: http://www.sekoia.fr/blog/windows-drive ... y-derusbi/
The philosophy is the same than Uroburos/Turla (exploit a vuln on a legit signed driver) but the implementation is completely different.
PS: I attached the sample.
P.
I published an article concerning a driver signing policy bypass there: http://www.sekoia.fr/blog/windows-drive ... y-derusbi/
The philosophy is the same than Uroburos/Turla (exploit a vuln on a legit signed driver) but the implementation is completely different.
PS: I attached the sample.
P.
Attachments
(209.39 KiB) Downloaded 109 times