Главная
Study mode:
on
1
Intro
2
INTRODUCTION
3
MINIMAL PROCESS
4
PICO PROCESS
5
PICO PROVIDERS
6
PICO PROVIDER SECURITY
7
WSL COMPONENT OVERVIEW
8
SYSTEM CALLS
9
DEVICE OBIECT INTERFACES
10
BUS INSTANCES
11
SOCKETS / FILES
12
BUS IPC MARSHALLING
13
BUS IPC DATA EXCHANGE
14
INITIAL ANALYSIS
15
ATTACK SURFACE ANALYSIS
16
PROCESS / THREAD NOTIFICATIONS & BEHAVIOR
17
CONCLUSION
Description:
Explore the hidden Linux kernel within Windows 10 in this 52-minute Black Hat conference talk. Dive deep into the implementation of "Project Astoria," which allows Windows to run native, unmodified Linux binaries. Learn about the Ring 0 driver with kernel privileges that enables this functionality, and understand its implications for security, including potential vulnerabilities and attack surfaces. Examine how this new paradigm affects security software, process management, and system calls. Discover the challenges posed by this integration, including the potential for Linux/Android malware to target Windows machines. Gain insights into the internals of this groundbreaking feature, uncovering design flaws and security challenges in Windows 10 Anniversary Update.

The Linux Kernel Hidden Inside Windows 10

Black Hat
Add to list
0:00 / 0:00