XaFF-XaFF / Cronos-Rootkit

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

win10 20H2 bluescreen

zjkanjie opened this issue · comments

commented

Process hide bluescreen

win10 20H2 19042.1466
Whether the program triggered PatchGuard?

bluescreen within about 30 minutes after loading

Can you help me? Thank you

怎么使用的?

yeah the rootkit unlinks the process from the ActiveProcessLinks, patchguard detects all those DKOM process hiding stuff so the repo is kinda outdated and for learning purposes I guess

commented

@xshiraori @zjkanjie Repo is discontinued and new features will be added to BlackAngel. Unfortunately, PatchGuard runs checks every 30 minutes and detects link changes. This problem probably also appears in BlackAngel. Once I have time, I'll try to solve this issue.