Delete CLAUDE.MD
This commit is contained in:
parent
ec6dd07488
commit
f806f09daa
1 changed files with 0 additions and 32 deletions
32
CLAUDE.MD
32
CLAUDE.MD
|
|
@ -1,32 +0,0 @@
|
||||||
# KVM Hypervisor Introspector
|
|
||||||
|
|
||||||
## Project
|
|
||||||
Rust-based KVM hypervisor introspector targeting a quickemu Windows 11 guest VM.
|
|
||||||
Performs live memory forensics from outside the guest OS (ring -1).
|
|
||||||
|
|
||||||
## Goals
|
|
||||||
- Walk guest EPROCESS list via CR3 + DirectoryTableBase
|
|
||||||
- Cross-view diff EPROCESS vs PspCidTable to detect DKOM-hidden processes
|
|
||||||
- Find rwx / non-image-backed VADs
|
|
||||||
- Inline asm for VMREAD/VMWRITE, CR3 manipulation, VMX instruction wrappers
|
|
||||||
- Or asm outside of inline
|
|
||||||
- possibly finding a vuln in qemu or quickemu however this would be difficult to do
|
|
||||||
|
|
||||||
## Stack
|
|
||||||
- Rust, `kvm-ioctls`, `vmm-sys-util`, `iced-x86`
|
|
||||||
- Target guest: quickemu Windows 11 VM on arch-uwu
|
|
||||||
- KVM via /dev/kvm ioctls
|
|
||||||
|
|
||||||
## Code Style
|
|
||||||
- No unnecessary comments inside of the code
|
|
||||||
- Unsafe blocks are expected and fine — document WHY not WHAT
|
|
||||||
- Inline asm preferred over wrappers where it's cleaner
|
|
||||||
- No clippy noise about unsafe
|
|
||||||
|
|
||||||
## Key Paths
|
|
||||||
- Guest VM socket/pid: resolve from quickemu at runtime
|
|
||||||
- Windows kernel offsets: hardcode initially for a known Win11 build, document the build
|
|
||||||
|
|
||||||
## Context
|
|
||||||
This is hackathon work. Prioritize working PoC over perfect architecture.
|
|
||||||
Security research / digital forensics framing.
|
|
||||||
Loading…
Add table
Reference in a new issue