Skip to content

Not possible to recover the VMK using WinPE based attack #3

@dummys

Description

@dummys

Hello,
I'm testing your version based on the winpe, everything works until I get the image of the memory, searchvmk didn't yield result.
My os is Win 11 24H2 enterprise. I tried to dump the memory of the booted computer and logedin, I was able to recover VMK using the searchvmk tool.
I checked the bootloader in the computer, and it is still signed with 2011 certificate, so wondering why attacks didn't work. Any idea on how I can debug it ?
Is it possible that Win 11 24H2 wipe VMK from memory when booting WinPE ?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions