You are on page 1of 48

www.alex-ionescu.

com
• Twitter: @aionescu
Example: Slack from Windows Store (File System )
▪ File System Virtualization ▪ “Application Silo”
Helium ▪
(Wcsifs.sys, Wcnfs.sys)
Registry Virtualization


Used by “Project Centennial”
Windows Bridge for Desktop
(Registry.sys + Native VReg) ▪ Increasing amount of apps
▪ Runs on Host, Modifies Host

▪ Object Manager Isolation ▪ “Server Silo”


Argon ▪

Network Virtualization (Wnv.sys)
Isolated Service Session


Windows Server Container
Docker for Windows
▪ PID/TID Filtering ▪ Supported on Server SKU Only
▪ Runs on Base OS Image ▪ Not a Security Boundary

Runs on Host, Cannot Modify HVSI


Krypton
▪ ▪
▪ Base Image Created On The Fly ▪ Windows Defender Application
▪ Thin Hyper-V Partition Guard (WDAG)
▪ “Project Barcelona”

Argon w/ Base OS Image Windows Container


Xenon
▪ ▪
▪ Thin Hyper-V Partition ▪ Docker For Windows
▪ Supported on Client SKU
▪ Security Boundary / No Bounty
Applications in Server Silo see a different “OS”
https://docs.microsoft.com/en-
us/virtualization/windowscontainers/about/

https://github.com/moby/moby/

You might also like