-
Notifications
You must be signed in to change notification settings - Fork 15
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Detected! #16
Comments
detected! |
hi, its not made to be undetected. |
I know bro! Zebra |
@BufferOverlord . Detected by...? Microsoft Defender? |
LOOK my github. i begin upload easy bootkit |
I know. Here are a list of things you forget to do:
|
Yeah thats good points for those who will want to improve the bootkit for anticheat bypass or anything else, ty. I have a good ability to remember peoples writing styles, didnt u that guy that im texting with on telegram about faceit cheat? :) |
yes im jonas from telegram... everytime a driver allocate memory or use the system api to do so, the anti cheat monitoring all process memory access. they see you allocating illegal memory. so instead, use direct assembly: cr3 change and atomic operation in real time for prevent they can read the last stack data from your process in memory then context switch happend, os save current register of a program to memory and begin executing other threads. that how process works. so by during this, you should be safe |
Yeah, now i better know what u mean, ty For example I have made in this month a driver cheat for faceit, that works with all 3 stages enabled (SB, TPM, HVCI) one example i can give is a thread spoofing/hiding. if u use a driver and tries to unlink a thread to make it stealth like some years ago people doing, your driver will be insta flagged as suspicious. its because no one legit driver is unlinking their thread, like why some driver needs to do it.(only in rare examples antiviruses driver can have abilities to do this type of things). and for now in 2025 its really more undetected if u doesnt do anything with your thread, because u cant fully hide it without disabling KPP. |
No description provided.
The text was updated successfully, but these errors were encountered: