// secciónsection · 4 artículos4 articles

Bajo nivelLow-level

Kernel, drivers, virtualización y firmware: lo que pasa por debajo de tu código.Kernels, drivers, virtualization and firmware: what runs beneath your code.

Bajo nivelLow-level · 12 min

Anatomía de un driver de Windows: del DriverEntry al IRPAnatomy of a Windows driver: from DriverEntry to the IRP

Qué pasa dentro de un driver de Windows: DriverEntry, IRQL, el viaje de un IRP, la tabla de dispatch, los IOCTL y por qué un spinlock mal usado tumba el sistema. Con código real.What happens inside a Windows driver: DriverEntry, IRQL, an IRP's journey, the dispatch table, IOCTLs and why a misused spinlock brings the system down. With real code.

Bajo nivel · Parte 3Low-level · Part 3 · 12 min

Ring -2: SMI, SMRAM y RSM, cómo el firmware toma la CPU por debajo del hipervisorRing -2: SMI, SMRAM and RSM, how firmware takes over the CPU below the hypervisor

Qué hay por debajo del hipervisor: System Management Mode, el código del firmware que se ejecuta a escondidas del sistema, y cómo comprobar desde C++ qué protecciones declara tu firmware.What lives below the hypervisor: System Management Mode, the firmware code that runs hidden from the OS, and how to check from C++ which protections your firmware declares.

Bajo nivel · Parte 2Low-level · Part 2 · 10 min

Ring -1: el hipervisor que vigila a tu kernelRing -1: the hypervisor watching over your kernel

Qué hay por debajo del kernel: el hipervisor, en modo VMX root (modo host de SVM en AMD). Cómo funciona con VT-x, AMD-V y EPT, por qué Windows usa uno para protegerse a sí mismo y cómo comprobarlo desde C++ con CPUID.What lives below the kernel: the hypervisor, in VMX root mode (SVM host mode on AMD). How it works with VT-x, AMD-V and EPT, why Windows uses one to protect itself, and how to check it from C++ with CPUID.

Bajo nivel · Parte 1Low-level · Part 1 · 11 min

De Ring 3 a Ring 0: qué pasa cuando tu código cruza la frontera del kernelFrom Ring 3 to Ring 0: what happens when your code crosses into the kernel

Un viaje por los anillos de privilegio del x86. Qué es el Ring 0, cómo funciona una syscall, por qué un fallo en el kernel tumba el sistema entero y qué defensas protegen hoy esa frontera.A journey through x86 privilege rings. What Ring 0 is, how a syscall works, why a kernel bug takes down the whole system, and which defenses guard that border today.