Scary protections in kernel? VBS can be bypassed. Memory integrity, hypervisor-protected code, still vulnerable. Let's discuss! #bsidesfrankfurt #bsides #bsidesfra #juansacco
Show transcript [en]
Let's talk about protections in kernel first. The most scary one that that still you can bypass is the BBS virtual asset based security is coming from the hypervisor. is hypervisor protected code integrity known as memory integrity.