YoVDO

The Linux Kernel Hidden Inside Windows 10

Offered By: Black Hat via YouTube

Tags

Black Hat Courses System Calls Courses Windows 10 Courses Attack Surface Analysis Courses

Course Description

Overview

Explore the hidden Linux kernel within Windows 10 in this 52-minute Black Hat conference talk. Dive deep into the implementation of "Project Astoria," which allows Windows to run native, unmodified Linux binaries. Learn about the Ring 0 driver with kernel privileges that enables this functionality, and understand its implications for security, including potential vulnerabilities and attack surfaces. Examine how this new paradigm affects security software, process management, and system calls. Discover the challenges posed by this integration, including the potential for Linux/Android malware to target Windows machines. Gain insights into the internals of this groundbreaking feature, uncovering design flaws and security challenges in Windows 10 Anniversary Update.

Syllabus

Intro
INTRODUCTION
MINIMAL PROCESS
PICO PROCESS
PICO PROVIDERS
PICO PROVIDER SECURITY
WSL COMPONENT OVERVIEW
SYSTEM CALLS
DEVICE OBIECT INTERFACES
BUS INSTANCES
SOCKETS / FILES
BUS IPC MARSHALLING
BUS IPC DATA EXCHANGE
INITIAL ANALYSIS
ATTACK SURFACE ANALYSIS
PROCESS / THREAD NOTIFICATIONS & BEHAVIOR
CONCLUSION


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube