Add example outputs for Slayer.sys and PoisonX.sys

This commit is contained in:
0xDbgMan
2026-04-27 14:22:08 +03:00
parent 9d44094ec5
commit c80ed86630
2 changed files with 262 additions and 0 deletions
+104
View File
@@ -0,0 +1,104 @@
╔═════════════════════════════════════════╗
║ DrvEye Windows Driver Rev&Analysis ║
║ Credit: @0xDbgMan ║
╚═════════════════════════════════════════╝
[*] Live MS block list: 889 SHA-1 + 870 SHA-256 hashes (4.4d old)
[*] Live MS trust list: 988 roots, 0 disallowed (4.4d old) [+972 new to kernel trust]
[*] Analysis started: PoisonX.sys
[*] SHA-256 : a5035cbd6c31616288aa66d98e5a25441ee38651fb5f330676319f921bb816a4
[*] imphash : 47c3554d0dee53d4f925ed52484bea12
[*] Architecture: x64 | Kernel Driver: Yes
[*] Image Base: 0x140000000 | Imports: 19 | Sections: 6
[*] Mitigations ON : HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, GS_COOKIE
[!] Mitigations OFF: FORCE_INTEGRITY, NO_SEH [HVCI:NO]
[*] ─── Authenticode Signature ───
[+] Status : crypto OK · anchor [ms-root-referenced] · cert expired (grandfathered by TS 2025-03-25)
[*] Primary : SHA256 [✓] signed by Microsoft Windows Hardware Compatibility Publisher
[*] → Microsoft Windows Third Party Component CA 2014
[*] Timestamp : 2025-03-25 [verified] (RFC3161)
[*] Anchor : Microsoft Root Certificate Authority 2010 [kernel-trusted]
[*] HVCI Prereqs: WHQL EKU
[*] Org : Microsoft Corporation
[*] Serial : 330000006E1229856F0ADE6CFC00000000006E
[*] Key : RSA-2048
[*] Valid : 2024-10-10 → 2025-10-08
[*] Thumbprint: a5d13378e659ddc05c03ee71b432dd667a302999
[*] Chain (2 certs):
[*] [0] Microsoft Windows Hardware Compatibility Publisher [CodeSign] [EXPIRED]
[*] Issuer: Microsoft Windows Third Party Component CA 2014
[*] Serial: 330000006E1229856F0ADE6CFC00000000006E
[*] Valid : 2024-10-10 → 2025-10-08
[*] [1] Microsoft Windows Third Party Component CA 2014 [CA]
[*] Issuer: Microsoft Root Certificate Authority 2010
[*] Serial: 330000000D690D5D7893D076DF00000000000D
[*] Valid : 2014-10-15 → 2029-10-15
[*] Scanning imports...
[+] ─── LOAD VERDICT: WILL LOAD (blocked only under HVCI) ───
Default Win10/11 : WILL LOAD
Secure Boot + DSE : WILL LOAD
HVCI / Memory Integrity : WILL NOT LOAD
• FORCE_INTEGRITY flag not set (HVCI requires it on the PE header)
Test-signing mode : WILL LOAD
S Mode : WILL NOT LOAD
• No Authenticode page hashes (Secured-Core requires per-page integrity)
All blockers found:
[BLOCKED] FORCE_INTEGRITY flag not set (HVCI requires it on the PE header)
[BLOCKED] No Authenticode page hashes (Secured-Core requires per-page integrity)
Passes:
[PASS] Any valid signature accepted under test-signing
[PASS] Chain anchored (ms-root-referenced)
[PASS] Signature crypto + PE hash OK
[PASS] Signed
[PASS] Signed 2025-03-25 (pre-expiry) — cert expiry ignored by Windows
[PASS] WHQL attestation EKU present
[PASS] WHQL attestation EKU present (Secured-Core ready)
Confidence: live MS trust list loaded (988 roots, 0 disallowed, 4.4d old)
Static checks cover signature crypto, PE hash, chain anchor, HVCI prereqs, and MS block list.
Not checked: live OCSP/CRL revocation, current WDAC policy, local test-signing / DSE state, page-hash integrity.
[*] imports Function:
[!] KeStackAttachProcess, ZwTerminateProcess
[*] ObReferenceObjectByName, IoCreateDevice, ZwOpenProcess
[*] Detected IOCTL codes (2):
0x0022E008 @0x1400017A2 (BUFFERED, FILE_READ_WRITE) → process kill [!!KILLER] bugs=process-kill [UNGATED-sink] [shares process-kill-site with 0x0022E010]
0x0022E010 @0x140001860 (BUFFERED, FILE_READ_WRITE) → process kill [!!KILLER] bugs=process-kill [UNGATED-sink] [shares process-kill-site with 0x0022E008]
[*] Exploit Primitives:
0x0022E008 (process kill): process-kill [@0x140001838 shared]
0x0022E010 (process kill): process-kill [@0x140001838 shared]
(1 unique primitive implementation(s) across 2 IOCTL tags — 1 shared by multiple IOCTLs)
[*] Recovered IOCTL Input Structures: 1 IOCTLs (use -v to show)
[!] Device Access Security:
Creation API : IoCreateDevice
Device Type : 0x22
Secure Open : Yes
Exclusive : No
SDDL : None (default permissive ACL)
Symlink : \DosDevices\{F8284233-48F4-4680-ADDD-F8284233} [user-accessible]
Symlink : \DosDevices\{F8284233-48F4-4680-ADDD-F8284233} [user-accessible]
Issues (4):
[!] Uses Iocreatedevice
[*] Not Exclusive
[*] Has Symlinks
[!] No Sddl
[*] ─── Device Names & Symbolic Links (3) ───
[*] \Device\{F8284233-48F4-4680-ADDD-F8284233} (kernel-only)
[+] \DosDevices\{F8284233-48F4-4680-ADDD-F8284233} (user-accessible) → CreateFile("\\.\{F8284233-48F4-4680-ADDD-F8284233}")
[+] \DosDevices\{F8284233-48F4-4680-ADDD-F8284233} (user-accessible) → CreateFile("\\.\{F8284233-48F4-4680-ADDD-F8284233}")
[+] ─── User-Mode Accessible Devices (1) ───
[+] \\.\{F8284233-48F4-4680-ADDD-F8284233} → \Device\{F8284233-48F4-4680-ADDD-F8284233}
[*] ─── Registry References (1) ───
(keys/values the driver reads — device name may be loaded here at runtime)
[r] RegistryValue:SymbolicLink
+158
View File
@@ -0,0 +1,158 @@
╔═════════════════════════════════════════╗
║ DrvEye Windows Driver Rev&Analysis ║
║ Credit: @0xDbgMan ║
╚═════════════════════════════════════════╝
[*] Live MS block list: 889 SHA-1 + 870 SHA-256 hashes (4.4d old)
[*] Live MS trust list: 988 roots, 0 disallowed (4.4d old) [+972 new to kernel trust]
[*] Analysis started: Slayer.sys
[*] SHA-256 : 3111f4d7d4fac55103453c4c8adb742def007b96b7c8ed265347df97137fbee0
[*] imphash : f6f2d5db1625547a53ee3ca65d01246f
[*] Architecture: x64 | Kernel Driver: Yes
[*] Image Base: 0x10000 | Imports: 52 | Sections: 6
[*] VersionInfo: OriginalFilename: EnPortv.sys | CompanyName: Guidance Software Inc. | FileVersion: | FileDescription: EnCase Driver
[*] Mitigations ON : none
[!] Mitigations OFF: HIGH_ENTROPY_VA, DYNAMIC_BASE, FORCE_INTEGRITY, NX_COMPAT, NO_SEH, GUARD_CF, GS_COOKIE [HVCI:NO]
[*] ─── Authenticode Signature ───
[+] Status : crypto OK · anchor [ms-root-referenced] · cert expired (grandfathered by TS 2008-11-20)
[*] Primary : SHA1 [✓] signed by Guidance Software, Inc.
[*] → VeriSign Class 3 Code Signing 2004 CA
[*] Timestamp : 2008-11-20 [accepted (legacy TSA — bind OK)] via VeriSign Time Stamping Services Signer - G2
[*] Anchor : Microsoft Code Verification Root [kernel-trusted]
[!] HVCI Prereqs: none (no WHQL/EV/page-hashes)
[*] Org : Guidance Software, Inc.
[*] Serial : 4F97F8F029BB92115E173AC1B62A8193
[*] Key : RSA-1024
[*] Valid : 2006-12-15 → 2010-01-31
[*] Thumbprint: 5c8561da9b14914806c8ee8595fdec811210198d
[*] Chain (5 certs):
[*] [0] VeriSign Time Stamping Services Signer - G2 [EXPIRED]
[*] Issuer: VeriSign Time Stamping Services CA
[*] Serial: 3825D7FAF861AF9EF490E726B5D65AD5
[*] Valid : 2007-06-15 → 2012-06-14
[*] [1] VeriSign Time Stamping Services CA [CA] [EXPIRED]
[*] Issuer: Thawte Timestamping CA
[*] Serial: 47BF1995DF8D524643F7DB6D480D31A4
[*] Valid : 2003-12-04 → 2013-12-03
[*] [2] VeriSign Class 3 Code Signing 2004 CA [CA] [CodeSign] [EXPIRED]
[*] Issuer:
[*] Serial: 4191A15A3978DFCF496566381D4C75C2
[*] Valid : 2004-07-16 → 2014-07-15
[*] [3] [CA] [EXPIRED]
[*] Issuer: Microsoft Code Verification Root
[*] Serial: 610C120600000000001B
[*] Valid : 2006-05-23 → 2016-05-23
[*] [4] Guidance Software, Inc. [CodeSign] [EXPIRED]
[*] Issuer: VeriSign Class 3 Code Signing 2004 CA
[*] Serial: 4F97F8F029BB92115E173AC1B62A8193
[*] Valid : 2006-12-15 → 2010-01-31
[*] Scanning imports...
[+] ─── LOAD VERDICT: WILL LOAD (blocked only under HVCI) ───
Default Win10/11 : WILL LOAD
Secure Boot + DSE : WILL LOAD
HVCI / Memory Integrity : WILL NOT LOAD
• FORCE_INTEGRITY flag not set (HVCI requires it on the PE header)
• W+X section present (HVCI forbids RWX)
Test-signing mode : WILL LOAD
S Mode : WILL NOT LOAD
• No WHQL attestation EKU — S Mode / Secured-Core require WHQL-signed drivers
• No Authenticode page hashes (Secured-Core requires per-page integrity)
All blockers found:
[BLOCKED] FORCE_INTEGRITY flag not set (HVCI requires it on the PE header)
[BLOCKED] No Authenticode page hashes (Secured-Core requires per-page integrity)
[BLOCKED] No WHQL attestation EKU — S Mode / Secured-Core require WHQL-signed drivers
[BLOCKED] W+X section present (HVCI forbids RWX)
Passes:
[PASS] Any valid signature accepted under test-signing
[PASS] Chain anchored (ms-root-referenced)
[PASS] Counter-sig binds to primary (2008-11-20); legacy TSA crypto — Windows CryptoAPI accepts it
[PASS] SHA-1 grandfathered (timestamped before 2015-07-29 kernel cutoff)
[PASS] Signature crypto + PE hash OK
[PASS] Signed
[PASS] Signed 2008-11-20 (pre-expiry) — cert expiry ignored by Windows
Confidence: live MS trust list loaded (988 roots, 0 disallowed, 4.4d old)
Static checks cover signature crypto, PE hash, chain anchor, HVCI prereqs, and MS block list.
Not checked: live OCSP/CRL revocation, current WDAC policy, local test-signing / DSE state, page-hash integrity.
[*] imports Function:
[!] KeAttachProcess, ZwTerminateProcess, ZwMapViewOfSection
[*] MmGetSystemRoutineAddress, PsLookupProcessByProcessId, ZwOpenProcess, ZwCreateFile, IoCreateDevice
[*] Detected IOCTL codes (25):
0x00223048 @0x141C0 (BUFFERED, FILE_ANY_ACCESS) → object access [!] any-user
0x0022304C @0x1412E (BUFFERED, FILE_ANY_ACCESS) → query process [!] any-user
0x00223050 @0x14097 (BUFFERED, FILE_ANY_ACCESS) → process attach [!!ATTACH] [!] any-user bugs=toctou-attach [shares process-attach-site with 0x00223054, 0x0022309C]
0x00223054 @0x13FE1 (BUFFERED, FILE_ANY_ACCESS) → process attach [!!ATTACH] [!] any-user bugs=toctou-attach [shares process-attach-site with 0x00223050, 0x0022309C]
0x00223058 @0x13F9E (BUFFERED, FILE_ANY_ACCESS) → stub (no observable calls) [!] any-user
0x0022305C @0x18E42 (BUFFERED, FILE_ANY_ACCESS) → stub (no observable calls) [!] any-user
0x00223064 @0x144B9 (BUFFERED, FILE_ANY_ACCESS) → validate addr [!] any-user bugs=toctou-attach [shares process-attach-site with 0x0022309C]
0x00223068 @0x1444C (BUFFERED, FILE_ANY_ACCESS) → process attach [!!ATTACH] [!] any-user [shares process-attach-site with 0x0022309C]
0x0022306C @0x143DF (BUFFERED, FILE_ANY_ACCESS) → registry access [!] any-user bugs=length-bounded
0x00223070 @0x14394 (BUFFERED, FILE_ANY_ACCESS) → file op [!] any-user
0x00223074 @0x1433A (BUFFERED, FILE_ANY_ACCESS) → registry delete [!!REG OP] [!] any-user
0x00223078 @0x142EC (BUFFERED, FILE_ANY_ACCESS) → process kill [!!KILLER] [!] any-user bugs=process-kill,toctou-attach [UNGATED-sink] [shares process-attach-site with 0x0022309C]
0x00223080 @0x1489D (BUFFERED, FILE_ANY_ACCESS) → token access [!!TOKEN STEAL] [!] any-user bugs=length-bounded,token-theft
0x00223084 @0x1483A (BUFFERED, FILE_ANY_ACCESS) → process access [!] any-user
0x00223088 @0x147B5 (BUFFERED, FILE_ANY_ACCESS) [!] any-user
0x0022308C @0x14720 (BUFFERED, FILE_ANY_ACCESS) → query process [!] any-user bugs=toctou-attach [shares process-attach-site with 0x00223090, 0x0022309C]
0x00223090 @0x14696 (BUFFERED, FILE_ANY_ACCESS) → query process [!] any-user bugs=toctou-attach [shares process-attach-site with 0x0022308C, 0x0022309C]
0x00223094 @0x145D9 (BUFFERED, FILE_ANY_ACCESS) → stub (no observable calls) [!] any-user
0x0022309C @0x14DA2 (BUFFERED, FILE_ANY_ACCESS) → process kill [!!KILLER] [!] any-user bugs=length-unbounded,process-kill,toctou-attach [shares process-attach-site with 0x00223050, 0x00223054]
0x002230A0 @0x14CA3 (BUFFERED, FILE_ANY_ACCESS) → process attach [!!ATTACH] [!] any-user bugs=length-unbounded,toctou-attach
0x002230A4 @0x14C5B (BUFFERED, FILE_ANY_ACCESS) [!] any-user
0x002230C0 @0x14BE7 (BUFFERED, FILE_ANY_ACCESS) → object access [!] any-user
0x002230C4 @0x14A39 (BUFFERED, FILE_ANY_ACCESS) → mem map [!] any-user bugs=arbitrary-rw
0x002230C8 @0x149BB (BUFFERED, FILE_ANY_ACCESS) → query process [!] any-user
0x00222058 @0x14F25 (BUFFERED, FILE_ANY_ACCESS) → trivial (completes IRP only) [!] any-user
[*] Exploit Primitives:
0x00223050 (process attach): process-attach [@0x11ACF shared]
0x00223054 (process attach): process-attach [@0x11ACF shared]
0x00223064 (validate addr): process-attach [@0x16160 shared]
0x00223068 (process attach): process-attach [@0x16E61 shared]
0x00223078 (process kill): process-attach [@0x16BEC shared], process-kill
0x00223080 (token access): token-steal
0x00223084 (process access): process-control
0x0022308C (query process): process-attach [@0x12C75 shared]
0x00223090 (query process): process-attach [@0x12C75 shared]
0x0022309C (process kill): process-attach [@0x11ACF shared]
0x002230A0 (process attach): process-attach
(9 unique primitive implementation(s) across 12 IOCTL tags — 5 shared by multiple IOCTLs)
[*] Recovered IOCTL Input Structures: 22 IOCTLs (use -v to show)
[!] Device Access Security:
Creation API : IoCreateDevice
Secure Open : No
Exclusive : No
SDDL : None (default permissive ACL)
Symlink : \DosDevices\<ServiceName> [user-accessible]
Symlink : \DosDevices\_root_ [user-accessible]
Issues (5):
[!] Uses Iocreatedevice
[*] No File Device Secure Open
[*] Not Exclusive
[*] Has Symlinks
[!] No Sddl
[*] ─── Device Names & Symbolic Links (4) ───
[*] \Device\NamedPipe (kernel-only)
[+] \DosDevices\<ServiceName> (user-accessible) → CreateFile("\\.\<ServiceName>")
[*] \Device\_root_ (kernel-only)
[+] \DosDevices\_root_ (user-accessible) → CreateFile("\\.\_root_")
[+] ─── User-Mode Accessible Devices (1) ───
[+] \\.\_root_ → \Device\_root_
[!] ─── Devices WITHOUT User-Mode Symlink (1) ───
(These cannot be opened from user-mode via CreateFile)
[-] \Device\NamedPipe
[*] ─── Registry References (1) ───
(keys/values the driver reads — device name may be loaded here at runtime)
[r] RegistryValue:SymbolicLink