diff --git a/CLAUDE.MD b/CLAUDE.MD deleted file mode 100644 index 07743be..0000000 --- a/CLAUDE.MD +++ /dev/null @@ -1,32 +0,0 @@ -# KVM Hypervisor Introspector - -## Project -Rust-based KVM hypervisor introspector targeting a quickemu Windows 11 guest VM. -Performs live memory forensics from outside the guest OS (ring -1). - -## Goals -- Walk guest EPROCESS list via CR3 + DirectoryTableBase -- Cross-view diff EPROCESS vs PspCidTable to detect DKOM-hidden processes -- Find rwx / non-image-backed VADs -- Inline asm for VMREAD/VMWRITE, CR3 manipulation, VMX instruction wrappers -- Or asm outside of inline -- possibly finding a vuln in qemu or quickemu however this would be difficult to do - -## Stack -- Rust, `kvm-ioctls`, `vmm-sys-util`, `iced-x86` -- Target guest: quickemu Windows 11 VM on arch-uwu -- KVM via /dev/kvm ioctls - -## Code Style -- No unnecessary comments inside of the code -- Unsafe blocks are expected and fine — document WHY not WHAT -- Inline asm preferred over wrappers where it's cleaner -- No clippy noise about unsafe - -## Key Paths -- Guest VM socket/pid: resolve from quickemu at runtime -- Windows kernel offsets: hardcode initially for a known Win11 build, document the build - -## Context -This is hackathon work. Prioritize working PoC over perfect architecture. -Security research / digital forensics framing.