Change User-Mode application’s virtual address through Kernel Debugging

Well, it’s somehow an odd topic but sometimes it could be really helpful in some situations. So what are the situations? Imagine sometimes you need to access windows stuffs that aren’t available from user-mode debuggers like ollydbg or through user-mode debugging (e.g memory after 0x7fffffff). In my experience I see some conditions that protectors make a sophisticated check for finding any debugger in memory and then change their approach to stop reverser from reversing the rest of the code. In…

How to get every detail about SSDT , GDT , IDT in a blink of an eye

  In a few days ago I was looking for something to show me the SSDT and GDT (Which is really important in malware analyzing because most of rootkits are interested in hooking and changing this stuffs.) • SSDT (System Service Descriptor Table) • GDT (Global Descriptor Table) • IDT (Interrupt Descriptor Table) They’re really important table in OSes for example SSDT is something like IAT (Import Address Table) in user-mode applications which holds pointer to exported functions of all…

A New Anti Ransomware Idea

In the last few days, I was asked to give a new idea for creating an anti ransomware and now I wanna share my idea and source codes. The Full Source Code Is Available at : Introduction In the raise of computers in this century and as they largely used in transferring and storing sensitive data, Ransomware is a big danger which can compromise everything in a blink of an eye and causes huge loss of data or money, according…

Kernel Mode Debugging by Windbg

Hey there, Today I’m gonna show you how to make a kernel mode debugging using VMWare and Windbg and Windows. So why should you do this ?! It’s clear , everything such as Kernel Mode Driver Debugging , searching for zero days and understanding windows mechanism. There are other types of kernel debugging as described in Windows Internals by Mark Russinovich that I describe in future posts. So let’s start. First you need a Windbg and as I’m working in a…

Hello World !

This is the first post of our blog ! After 5+ years of experience working with various technologies and developing skills in different computer fields including security and network, we want to share our little knowledge of this huge science to all people who love computers and computer security. As you know this year is a leap year and today is the last day of the year and tomorrow is the new year. (In Persian Calendar 😉 ).so that’s like the anniversary…