Kernel Module Signature Verification Architecture Simulator
CONFIG_MODULE_SIG_FORCE=y
Signed Module (.ko)
Unsigned Module
Tampered Module
Mode: Enforce (sig_enforce=1)
Next Step ⏭
Auto Play ▶
Reset ↺
Theme 🌓
Userspace insmod / finit_module
Official Signed Module
ELF + PKCS#7 / CMS
~Module signature append~
Unsigned Rootkit (.ko)
Raw ELF executable
No PKCS#7 trailer
Missing cryptographic proof
Tampered Module
ELF byte modified by attacker
PKCS#7 signature present
SHA-256 hash mismatch
Kernel Module Verification
CONFIG_MODULE_SIG_FORCE=y (sig_enforce=1)
module_sig_check()
Extracts PKCS#7 signature block
Computes SHA-256 over ELF binary
Verifies against .builtin_trusted_keys
Trusted Kernel Keyring
Keyring: .builtin_trusted_keys
X.509 Root CA / Ephemeral Key
Enforce=1: Denies unsigned/bad sig
Status: Strict enforcement active
Kernel Load Outcome
MODULE LOADED
Return: 0 (Success)
Linked into kernel space
Driver init() executed
LOAD REJECTED
Error: -ENOKEY / -EKEYREJECTED
Module memory released
Rootkit injection thwarted
No Ring 0 execution
Ready. Choose a scenario: Signed Module, Unsigned Module, or Tampered Module.
Step: 0/4