BATTLE OF SKM AND IUM
blackhat2015
blackhat2015
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
VSM / HYPERVISOR LAUNCH<br />
• VSM is a built-in feature of the Hyper-V 5.0+ hypervisor (Windows 10 / Server 2016)<br />
• Enabling Hyper-V with the “hypervisorlaunchtype” BCD variable will enable VSM<br />
• But nothing executes at VTL 1 (yet)<br />
• When the hypervisor is configured to launch, OslArchHypervisorSetup will eventually call<br />
HvlpLaunchHvLoader<br />
• This launches HVLOADER.EFI, which is the boot loader for Hyper-V itself<br />
• Later, in the second phase of the bootloader, OslArchHypervisorSetup runs again, and starts the hypervisor<br />
• With the Hypervisor fully active and initialized, the rest of the boot loader’s execution is itself running<br />
under the root partition<br />
• Note: this is a change from Windows 7, where the hypervisor was initialized much later through a boot driver