A deep dive into Microsoft Warbird: MS's kernel-mode dynamic packer.
English, DutchMicrosoft Warbird is a kernel-mode dynamic packer that works even in an HVCI-protected kernel. In this blog post, we will reverse engineer and analyze its inner workings.