ZeroMemoryEx / Chaos-Rootkit

Now You See Me, Now You Don't

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

It has been deleted by Windows defender, is there any way to let Windows defenders, such as confusion?

lian666666 opened this issue · comments

commented

Yes, it was deleted by the antivirus because it was uploaded. So, you have to disable it before testing it. Also, please use a virtual machine because the rootkit can be unstable for the system at some point.

It's okay, I don't have administrator privileges, I plan to use it to elevate privileges,
And I can't turn off the antivirus

commented

It's just a research project. To do this, you would need a certificate or a vulnerable driver, or an exploit to disable PatchGuard. Once you have done this, you can load it

How to craft a certificate or a vulnerable driver, or a bug that disables PatchGuard to let software bypass windows defenders. At present, I only know obfuscation software to bypass windows defenders, and I don't know how to do it