Quantcast
Channel: Active questions tagged kernel - Stack Overflow
Viewing all articles
Browse latest Browse all 6502

How to create a process with PsProtectedSignerAntimalware flag set if i already have a kernel driver?

$
0
0

How do some processes in Windows get the PsProtectedSignerAntimalware flag set for them? Meaning how does windows decide which processes should have this flag set when they are created?

More info regarding this flag :

https://www.crowdstrike.com/blog/evolution-protected-processes-part-1-pass-hash-mitigations-windows-81/

I doubt that Microsoft has hardcoded the list of AntiViruses somewhere and decides which processes should get this flag based on the certificate, so how does windows decide which processes should get this flag?

Lets say i already have a driver loaded, is there anyway i can force my user-mode processes to have this flag?


Viewing all articles
Browse latest Browse all 6502

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>