win10 20H2 bluescreen
zjkanjie opened this issue · comments
Process hide bluescreen
win10 20H2 19042.1466
Whether the program triggered PatchGuard?
bluescreen within about 30 minutes after loading
Can you help me? Thank you
怎么使用的?
yeah the rootkit unlinks the process from the ActiveProcessLinks, patchguard detects all those DKOM process hiding stuff so the repo is kinda outdated and for learning purposes I guess
@xshiraori @zjkanjie Repo is discontinued and new features will be added to BlackAngel. Unfortunately, PatchGuard runs checks every 30 minutes and detects link changes. This problem probably also appears in BlackAngel. Once I have time, I'll try to solve this issue.