May 7, 2024, 11:56 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

A while ago, I was working on adding support for Windows kernel debugging in our debugger. It did not take me long to make the typical two-machine remote kernel debugging work since we already have code to leverage the DbgEng API. The only difference for starting a kernel debugging session is to call AttachKernel instead of CreateProcess2.


However, I was unable to quickly figure out how to start a local kernel debugging session. The documentation does not mention it! …

api binary binary ninja code debugger debugging fun kernel machine malware analysis profit session support windbg windows windows kernel work working

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior Security Analyst

@ Oracle | United States

Associate Vulnerability Management Specialist

@ Diebold Nixdorf | Hyderabad, Telangana, India

Cybersecurity Architect, Infrastructure & Technical Security

@ KCB Group | Kenya