PSA @surface book 3 and all new Surface devices have HVCI and VBS on by DEFAULT which enforces a driver block policy that blocks RWET and other bad drivers. Security vendors are going to tell you need to buy their stuff, but Windows has everything you need to block it.https://twitter.com/GossiTheDog/status/1334460570930733057 …
-
-
Replying to @dwizzzleMSFT @surface
There's a plenty of similar drivers that works even with HVCI enabled
1 reply 0 retweets 1 like -
Nope. Simply run a policy that builds an allow list tailored to your device. The default blocklist is the low bar because it must work on a billion PCs where a vuln driver might have a boot dependency. If it blocked that aggressively it could DoS people
2 replies 0 retweets 4 likes -
furthermore, if you don't want to build a full blocklist, you can just switch to "WHQL" only that narrows the funnel tremendously.
1 reply 0 retweets 1 like -
Replying to @dwizzzleMSFT @surface
Dmytro Oleksiuk Point Never Retweeted Dmytro Oleksiuk Point Never
WHQL only is not a panacea here, even close. I'm using WHQL signed WinIo.sys variation in my Hyper-V backdoorhttps://twitter.com/d_olex/status/1334497509830324227 …
Dmytro Oleksiuk Point Never added,
1 reply 1 retweet 1 like -
dude who said Panacea you're such a hype artist.
1 reply 0 retweets 0 likes -
Replying to @dwizzzleMSFT @surface
Dude, unlike you I'm not trying to sell anything at least
1 reply 0 retweets 0 likes -
clearly trying to sell yourself with a bunch of hyperbole
1 reply 0 retweets 0 likes -
Replying to @dwizzzleMSFT @surface
I don't have a need to "sell myself" because I'm not working in IT and not even planning. Why should I "sell myself" when I already have a bunch of job offers (which I don't care about) from top tech companies
1 reply 0 retweets 0 likes -
i think he just called you a whore....
1 reply 0 retweets 1 like
but hey- the whore is correct here, for all meaningfull intents its still easy to load driver that allows you to map physical memory
-
-
It's better to be a whore than someone naive enough who relies on MS bug bounty as main source of income and then starts to cry on twitter about wHeRe iS mY mOnEy I cAnT pAy FoR mY hOuSe
1 reply 0 retweets 0 likes -
i didnt call you anything - i just said you where correct. but sure ill just agree with your statement there :)
1 reply 0 retweets 0 likes - Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.