Akash Trehan
Blog

Patch or attack? How Windows proves a kernel change is legit

How the Windows Secure Hotpatch Report uses VTL1 attestation to tell legitimate hotpatches from kernel tampering. Full post coming soon.

By Akash Trehan · · 1 min read
The Windows Secure Hotpatch Report: a modified region in ntoskrnl.exe branching to 'a cheat?' or 'a Microsoft hotpatch?', answered by a signed report.

The full post is on its way. I’m putting the finishing touches on it. It’ll cover the Windows Secure Hotpatch Report: the signed, VTL1-attested list of every active kernel and driver hotpatch on a machine, and how anti-cheat and security tools can use it to tell a legitimate Microsoft patch apart from tampering.

In the meantime, the working sample is already up on GitHub. Clone it, build it with the Windows SDK, and try it today:

github.com/CodeMaxx/windows-runtime-attestation-report

Check back shortly for the full writeup. Thanks for stopping by!