Today is a big day. Finally the PhantomSensor the Kernel driver of our ShadowStrike EDR/XDR platform completely finished.We ran the analysis through the best static analysis tools on the market (PVS-Studio + Coverity), then through Microsoft's CodeQL (formerly SDV). I've been working on this for days, 15-16 hours a day, and now these analyses are finally complete.
[Coverity Dashboard Screenshot]
https://scan.coverity.com/projects/ShadowStrike-Labs-ShadowS...
The next step is to test using Driver Verifier in Microsoft's hypervisor, and then, using Fuzzer, we will apply fuzzing tests to the critical IOCTL-requiring parts of the driver.
All code auditable. GitHub Sponsors live!
Github: https://github.com/ShadowStrike-Labs/ShadowStrike