Skip to content
This repository has been archived by the owner on Apr 26, 2021. It is now read-only.

Integrate Zer0m0n project or develop kernel monitoring #490

Open
Tigzy opened this issue Mar 5, 2015 · 5 comments
Open

Integrate Zer0m0n project or develop kernel monitoring #490

Tigzy opened this issue Mar 5, 2015 · 5 comments
Assignees
Labels
Milestone

Comments

@Tigzy
Copy link

Tigzy commented Mar 5, 2015

Hello
There's a fact, malware can easily detect cuckoo hooks, even with the DLL hidden.
Why not go deeper and do the analysis from kernel mode?

This is what zer0m0n does, why not integrate its development into cuckoo official repo?
https://github.com/conix-security/zer0m0n

@jbremer
Copy link
Member

jbremer commented Mar 5, 2015

Hi,

Yes, thanks for the reminder, it has been on my todo list for quite a while, but I have to find the time for it to properly integrate it upstream ;)

Jurriaan

@Tigzy
Copy link
Author

Tigzy commented Mar 5, 2015

Good to hear 👍
Keep up the good work!

@botherder
Copy link
Member

There are several reasons why monitoring was kept in userland. Kernelmode monitoring doesn't give as much granularity and flexibility in what we can do. Besides being an incredible hassle to maintain for multiple platforms in the long run.

For what it's worth, we won't replace usermode hooking with kernelmode. Perhaps make them complementary at most.

@Tigzy
Copy link
Author

Tigzy commented Mar 6, 2015

"Kernelmode monitoring doesn't give as much granularity and flexibility in what we can do".
Well, all NtXxxx APIs hooked in userland have their kernelmode equivalent with ZwXxxx.

I agree with the fact hooking SSDT isn't an easy task on multiple platforms, but the researcher can help a little bit on modern OSs with disabling patchguard. Not asking to replace the userland hooking but provide an option to choose a preferred way.

@jbremer jbremer self-assigned this Mar 23, 2015
@botherder botherder added this to the 2.0 milestone Apr 1, 2015
@botherder botherder changed the title Feature: Integrate Zer0m0n project (?) or develop kernel monitoring Integrate Zer0m0n project or develop kernel monitoring Apr 1, 2015
@ghost
Copy link

ghost commented Jan 9, 2019

How is the development going on for this feature ? Any release dates yet ?

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

3 participants