Categories: GeSWall's Security Tests, Key Loggers, Rootkits

Advanced Process Termination

01/14/07 Posted by geswall

Advanced Process Termination provides numerous options to terminate given processes. GeSWall enforces its policy by means of kernel mode driver and termination of the processes doesn’t impose a direct threat to GeSWall. However, it is a good test for the… more »

Network Shares Access

01/02/07 Posted by geswall

There is a known trick to bypass DropMyRights - using a network share on loop-back interface, e.g: ren \\localhost\c$\windows\system32\malware.exe cmd.exe That is limitation of remote impersonation. DropMyRights creates a restricted token which cann… more »

KeyHook demo

12/08/06 Posted by geswall

Keyhook is a demo keylogger. This demo uses for the global keyboard hook to intercept key strokes with keyhook.dll. GeSWall prevents interception of key strokes in other processes. The interception prevented by disabling global hook and loading u… more »

Advanced Process Manipulations

11/23/06 Posted by geswall

DiamondCS's Advanced Process Manipulations (APM) is an advanced process/module viewer and manipulation utility that allows flexible control over target processes. GeSWall blocks all operations with the processes from within isolated APM Lin… more »

RegHide

11/12/06 Posted by geswall

RegHide demonstrates how the Native API can be used to create object names that are inaccessible from the Win32 API. While there are many different ways to do this, the method used here it to include a terminating NULL that is explicitly made part of th… more »

1 2 3 >>