Repository navigation
Conversation
Replace kernel signature scanning with a user-mode resolver that stores validated RVAs for the matching Windows kernel. BREAKING CHANGE: installation now requires vmloader_resolver.exe and valid registry symbol data before driver start.
- Rename RemoveSignatures to ReplaceInPlace to support pattern replacement instead of just removal - Add Replacement parameter to enable substituting detected patterns with alternative strings - Replace VMware/Virtual strings with System/Generic equivalents in firmware tables - Add RemoveEnumerationEntry function to filter ACPI table entries from enumeration lists - Add TableIdMatches helper to check table IDs in both native and reversed byte order - Add RecomputeAcpiChecksum function to recalculate ACPI table checksums after modifications - Implement WAET table filtering in FilterAcpi to prevent enumeration and return STATUS_NOT_FOUND - Enhance FilterAcpi to handle both enumeration (Action 0) and table access (Action 1) requests - Update FilterRsmb to use new ReplaceInPlace function with proper string substitution - Fix loop boundary calculation in pattern search to prevent off-by-one errors - Update compiled vmloader.sys binary with new firmware filtering logic
- Add new pnp_hook module with PnP callback registration and device filtering - Implement case-insensitive pattern matching for VMware device detection (VEN_15AD, VID_0E0F) - Filter PCI, USB, and HDAUDIO device enumeration to hide VMware devices - Add registry key enumeration hooks to mask VMware presence from user-mode queries - Integrate PnP hook installation and removal into driver lifecycle - Update VmLoader.vcxproj and filters to include new source and header files - Initialize PnP hooks during DriverEntry with proper error handling and cleanup
feat(symbols): resolve kernel globals from PDB
Co-Authored-By: Codex <codex@openai.com>
Co-Authored-By: Codex <codex@openai.com>
使用 PsLoadedModuleResource 共享锁保护。 遍历 PsLoadedModuleList,匹配 ntoskrnl.exe。 使用 RtlImageNtHeaderEx 按映像大小校验 PE 头。 增加异常捕获及完整的锁释放路径。 移除 MmGetSystemRoutineAddress + RtlPcToFileHeader 方案。
主要改动: 增加内核描述表,关联文件名、KPH class 和 fields size。 FindRunningKernel 按 KSI 顺序识别两种内核,并返回统一 identity。 external/embedded lookup 均向 KphDynDataLookup 传递实际 class。 保留原有 PE header、writable/non-executable section 和 RVA 校验。 增加日志输出实际内核名称与 class。 同步更新运行时文档。
自动申请管理员权限。 复用有效的 VmLoader Test Signing 证书。 缺失时生成 RSA 3072/SHA-256 测试证书。 将证书加入本机 Root 和 TrustedPublisher。 自动查找 Windows SDK signtool.exe。 签名并验证 VmLoader.sys。
主要改动: 移除 Win32/x86 工程与解决方案配置,默认平台改为 x64。 新增 Debug/Release ARM64 解决方案映射。 ARM64 启用 KPH 头文件、消息编译、ksecdd.lib、动态数据生成及签名。 ARM64 产物独立发布到 bin\ARM64,避免覆盖 x64。 同步更新 README 与 Serena 项目记忆。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Validation
Runtime behavior was not exercised in a disposable Windows VM in this environment.