logo

Windows Internals: Dissecting Secure Image Objects - Part 1

ID: 6d4a732e-1994-5d0b-99ee-6511d6f3427f

STIX ID: report--6d4a732e-1994-5d0b-99ee-6511d6f3427f

Feed Name: Connor McGarr’s Blog

Date Published: 2024-06-01

Date Updated: 2026-04-19

Author: Connor McGarr

...
...

This blog post reverse-engineers how Windows’ Secure Kernel and SKCI create and manage Secure Image objects to support HVCI/Kernel CFG during driver loads, tracing the Secure System Call path (VslCreateSecureImageSection → IumInvokeSecureService → SkmmCreateSecureImageSection → SkciCreateSecureImage), detailing how VTL1 maps and validates VTL0-provided MDLs/PFNs for image headers, identifies SHA-256 (0x800C) use and the creation of Image/Page Hash contexts, and outlines the Secure Image fields captured (sections, relocations, load config, prototype PTE references) and sparse-table/object-type management, including handle return to NT, setting the stage for later validation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.