sorry for late, these have been some very busy days :-/
Yes, we considered that :-) Our idea was to use an user-space program
that waits for notifications from hyperdbg and then takes car of
interacting with windows event logger. We already developed and
deployed a stub user-space --> hyperdbg communication scheme through
the use of VMCALL instruction. In a couple of weeks I (hopefully) will
be able to get back to the code and I am planning to implement some
more "user-space to hypervisor" functionalities :-)
Cheers,
Aristide
--
GnuPG Key on keyserver.pgp.com ID 0x25578128
http://security.dico.unimi.it/~joystick/