Windows System Software -- Consulting, Training, Development -- Unique Expertise, Guaranteed Results

Home NTFSD
Before Posting...
Please check out the Community Guidelines in the Announcements and Administration Category.

More Info on Driver Writing and Debugging


The free OSR Learning Library has more than 50 articles on a wide variety of topics about writing and debugging device drivers and Minifilters. From introductory level to advanced. All the articles have been recently reviewed and updated, and are written using the clear and definitive style you've come to expect from OSR over the years.


Check out The OSR Learning Library at: https://www.osr.com/osr-learning-library/


How to verify signatures of a PE in kernel mode?

ANTUCWANTUCW Member Posts: 9

I am writing a mini-filter driver and I need to check the signature of a PE file in it. I know how to do it in user mode and it works fine. Now I need to do the same in my driver, I am clueless. Any suggestions on how to verify PE signatures in kernel mode?

Thanks in advance. Can you provide any solution.

Comments

  • Scott_Noone_(OSR)Scott_Noone_(OSR) Administrator Posts: 3,260

    Do it in user mode. See FltCreateSectionForDataScan.

    And, just for completeness, this does only check the signature of the file on disk. It might not really have anything to do with the running executable (e.g. due to process hollowing).

    -scott
    OSR

  • ANTUCWANTUCW Member Posts: 9

    HI i am trying to find the file type by reading first four bytes of a file. can you provide any solution for this.

  • AlbertAlbert Member - All Emails Posts: 409
    via Email
    How about using Windows code integrity apis?
  • Scott_Noone_(OSR)Scott_Noone_(OSR) Administrator Posts: 3,260

    @ANTUCW I have now replied to three of your posts. Each time you have ignored the response and just asked the same question again. Clearly you're not looking for help and just want/need someone to give you code to do this so I'm going to stop wasting my time.

    -scott
    OSR

Sign In or Register to comment.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Upcoming OSR Seminars
OSR has suspended in-person seminars due to the Covid-19 outbreak. But, don't miss your training! Attend via the internet instead!
Kernel Debugging 30 Mar 2020 OSR Seminar Space
Developing Minifilters 15 Jun 2020 LIVE ONLINE
Writing WDF Drivers 22 June 2020 LIVE ONLINE
Internals & Software Drivers 28 Sept 2020 Dulles, VA