Skip to content

Not possible to recover the VMK using WinPE based attack #3

Description

@dummys

Hello,
I'm testing your version based on the winpe, everything works until I get the image of the memory, searchvmk didn't yield result.
My os is Win 11 24H2 enterprise. I tried to dump the memory of the booted computer and logedin, I was able to recover VMK using the searchvmk tool.
I checked the bootloader in the computer, and it is still signed with 2011 certificate, so wondering why attacks didn't work. Any idea on how I can debug it ?
Is it possible that Win 11 24H2 wipe VMK from memory when booting WinPE ?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions