is the ntoskrnl.exe the binary that’s running the “System” process of Windows OS? We need a procedure of validating the integrity of the windows OS “System” process… Which binaries need to be tested for verifying the “System” process integrity?
yeap, right, the sys process is loading drivers and so on… I think I will abandon the idea… the whole thing was about checking for microsoft signatures the main binary running the OS.