There are 4 repositories under patchguard topic.
Disable PatchGuard and Driver Signature Enforcement at boot time
Defeating Patchguard universally for Windows 8, Windows 8.1 and all versions of Windows 10 regardless of HVCI.
InfinityHookPro Win7 -> Win11 latest
Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard
Windows 11 24H2-25H2 Runtime PatchGuard Bypass
x64 Windows PatchGuard bypass, register process-creation callbacks from unsigned code
Kernel Level NMI Callback Blocker
runtime patchguard disabler (win 10 & 11)
EPROCESS Unlinking example in "C" using DKOM Manipulation
A single byte modification in the kernel memory bypasses and disables all core functions of the AV/EDR security solutions
PsLoadedModuleList Unlinking through DKOM Manipulation
Kairos is a next-generation, red-team-oriented Windows kernel defense neutralization framework. It combines traditional runtime patching with UEFI persistence, hypervisor-level surveillance, and Secure Kernel deception.
Small modifications from BugChecker, build a KDCOM.dll to lure the Windows Kernel into believing that it is beeing debugged to deactivate PatchGuard
22h2 Windows patchguard runtime disabler.
Demonstration code for intercepting and disabling NMI handling on Intel CPUs in Windows kernel mode.
Automatic EfiGuard build using Github Action with replacing GUID, VARIABLE NAME and COOKIE.