Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Using PoolTags to Fingerprint Hosts #231

Open
hfiref0x opened this issue Apr 7, 2021 · 3 comments
Open

Using PoolTags to Fingerprint Hosts #231

hfiref0x opened this issue Apr 7, 2021 · 3 comments

Comments

@hfiref0x
Copy link
Contributor

hfiref0x commented Apr 7, 2021

This article may spark some interest.
https://labs.nettitude.com/blog/using-pooltags-to-fingerprint-hosts/

tl;dr; you can built table of specific pool tags used by vm drivers when allocating memory and then use it as vm detection vector.

This article provides complete example and this system information should be available starting from ancient times up to modern Win10 versions.

@gsuberland
Copy link
Collaborator

Embarrassed to admit that I didn't know this trick, since I not only work at Nettitude but have worked with Kyriakos at two different companies!

@ayoubfaouzi
Copy link
Owner

Thanks @hfiref0x

When I saw the link, my initial taught that it was your post @gsuberland :)

@gsuberland
Copy link
Collaborator

Speaking of which, part 3 of my series is out. I'll open a new issue for it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants