Disabling - PatchGuard - Kernel Patch Protection (KPP)

Costas

Administrator
Staff member
In January 2006, security researchers known by the pseudonyms "skape" and "Skywing" published a report that describes methods, some theoretical, through which Kernel Patch Protection might be bypassed. Skywing went on to publish a second report in January 2007 on bypassing KPP version 2, and a third report in September 2007 on KPP version 3. Also, in October 2006 security company Authentium developed a working method to bypass KPP.

src - https://en.wikipedia.org/wiki/Kernel_Patch_Protection



https://github.com/hfiref0x/UPGDSED
https://github.com/arielkoren/DisablePatchGuard
https://libertas.lt/code/patchguard/





A patch for InfinityHook was once additionally shipped in Home windows Insider builds in September, and is possibly incorporated with Home windows 10 v1909, launched previous this month.



https://github.com/everdox/InfinityHook




Turkish software developer Can Bölük. Develop ByePG is considered even more dangerous, as it can bypass both PatchGuard and Hypervisor-Protected Code Integrity (HVCI), a feature that allows Microsoft to blacklist bad drivers on users' devices.


https://github.com/can1357/ByePg

ref - https://www.zdnet.com/article/new-bypass-disclosed-in-microsoft-patchguard-kpp/



Disable PatchGuard and DSE at boot time

https://github.com/Mattiwatti/EfiGuard
 
Top