Windows main OS binary question

Home Forums Discussions General Discussion Windows main OS binary question

This topic contains 2 replies, has 2 voices, and was last updated by  Deneb 11 years, 12 months ago.

Viewing 3 posts - 1 through 3 (of 3 total)
  • Author
  • #5098



    is the ntoskrnl.exe the binary that’s running the “System” process of Windows OS? We need a procedure of validating the integrity of the windows OS “System” process… Which binaries need to be tested for verifying the “System” process integrity?


    Vadim Smirnov

    Any kernel module can run a thread in the context of the system process, what integrity do you mean here?



    yeap, right, the sys process is loading drivers and so on… I think I will abandon the idea… the whole thing was about checking for microsoft signatures the main binary running the OS.

Viewing 3 posts - 1 through 3 (of 3 total)

You must be logged in to reply to this topic.