For quite some time ive been suspecting that ive been bootkitted. Suddenly I couldnt read my SMBIOS table, windows detected a hyper visor even when disabled with bcdedit. I could find traces of vpn connections getting established to MS ip addresses.
-
-
-
The same enviroment used for WDAG/Sandbox. I havent figured out exactly how the boot process works-or maybe I have, I just need to verify.
Show this thread -
So, in the "bootos" we find this: This indicate that there is at minimum capability to deploy shielded VMs. I think they would be deployed using the new TPM 2.0 deployment method.pic.twitter.com/GMGpfMrB5m
Show this thread -
https://pastebin.com/raw/DcpWEvRX there is a new trustlet that is used for a cross vm pki hierarchy
Show this thread -
This I think is the "container os", then nested virtualization is used in additiononpic.twitter.com/BTepEPF84N
Show this thread -
-
-
bootsvc.dll - used for booting up into a layered filesystem disc - part of storage spaces I thinkpic.twitter.com/QtIkfNGyAb
Show this thread -
I think maybe this file enabling altering the bootflow, my recovery wim file grows to 700 from 400 and I think it always boot into the os in there first? This do not seem like a good idea as by default the recovery partition allow unprivileged users to writepic.twitter.com/81iG55uxY9
Show this thread -
This log file I think is about the "setupos" , another os it can boot into to do updatespic.twitter.com/qNUUbTGmAU
Show this thread -
It appears dtrace is loaded by the vail os - and that is not the os that I am in... vail also seems to prepare vm images and launch them....pic.twitter.com/ZEdfaTuj84
Show this thread -
ok - I think that vail is inside the recovery.wim , it is a shielded hidden vm, it seems to be debugging the hypervisor. It is what launches other vms https://pastebin.com/raw/xz4Ah57j
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.