Package rekall :: Package plugins :: Package windows :: Package gui
[frames] | no frames]

Package gui

source code

These plugins implement analysis of the win32k graphic subsystem.

This work stemmed from the seminal work:

Kernel Attacks through user mode callbacks Tarjei Mandt.

http://mista.nu/blog/2011/08/11/windows-hooks-of-death-kernel-attacks-through-user-mode-callbacks/

Other interesting references: http://volatility-labs.blogspot.de/2012/09/movp-13-desktops-heaps-and-ransomware.html

Submodules

Variables
  __package__ = 'rekall.plugins.windows.gui'