microsoft / microsoft/AttackSurfaceAnalyzer

Check Kernel Module Signatures

Open
#507 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement
Dominant language
C#
Stars
3k
Forks
294
PR merge metrics
No merged PRs in 30d

Description

We enumerate kernel modules when enumerating drivers. Those can have a signature and we should check it when possible. It looks like we may have to reimplement this perl script's behavior.

https://unix.stackexchange.com/questions/493170/how-to-verify-a-kernel-module-signature

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue names no file or test; start by locating the existing driver-enumeration entry point and compare its kernel-module handling with the behavior described in the linked Unix Stack Exchange reference. Determine what signature information can be checked when supported, then verify that enumeration reports it; done means kernel-module signatures are checked where possible.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp, perl
Domain
operating-systems, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.