Вы находитесь на странице: 1из 27
















• Neither debuggers nor sandboxes were designed for this
• We face a tradeoff between visibility/flexibility and
isolation/evasion resistance
• We are not aware of any tool that combines these properties
1
Virtualization Layer

Guest Operating •
System

Virtual Hardware
Hypervisor
1
Virtualization Layer

Guest Operating •
System

2

Virtual Hardware
VMI
Hypervisor
10100101001001000110100010111101010010110100010101110110
01101000101011101100010001011110101001001011100101100010
11110100010101110110000101010011110101001110010100001010
00001011101100010001011110100101001001000110100010111101
01110110000101010011110101100010101110110001000101111010
10010010111001011000101111010001010111011000010101001111
01010011100101000010100000101110110001000101111000011010
01110110000101010010100010010010100001001010001001000001
01111101010101111011110101100010101110110001000101111010
10010010111001011000101111010001010111011000010101001111
10100101001001000110100010111101010010110100010101110110
01101000101011101100010001011110101001001011100101100010
ruct _EPROCESS {
11110100010101110110000101010011110101001110010100001010
_KPROCESS Pcb;
00001011101100010001011110100101001001000110100010111101
_EX_PUSH_LOCK Proces
01110110000101010011110101100010101110110001000101111010
_LARGE_INTEGER Creat
10010010111001011000101111010001010111011000010101001111
_LARGE_INTEGER ExitT
01010011100101000010100000101110110001000101111000011010
_EX_RUNDOWN_REF Run
01110110000101010010100010010010100001001010001001000001
DWORD64 UniqueProc
01111101010101111011110101100010101110110001000101111010
LIST_ENTRY Active
10010010111001011000101111010001010111011000010101001111
1
Virtualization Layer

Guest Operating •
System


2 3

Virtual Hardware Semantic


VMI
Hypervisor Layer
1 4
Virtualization Layer

Interactive
Interface •
Guest Operating
System

2 3

Virtual Hardware Semantic •


VMI
Hypervisor Layer
1

Guest Operating

System


Virtual Hardware
KVM
QEMU
1

Guest Operating

System

Virtual Hardware •
2
KVM
VMI QMP
QEMU
1 3
Rekall

Guest Operating

System

Virtual Hardware
rVMI Plugins •
2 QMP
KVM
VMI QMP Client
QEMU Rekall Core
1 3
Rekall
4 4

Guest Operating
Python •
System iPython
API


Virtual Hardware
rVMI Plugins
2 QMP •
KVM
VMI QMP Client
QEMU Rekall Core





Вам также может понравиться