Company: Wow, it seems like many of these ransomware groups try to turn off Windows Defender. Hey, we could use this Tamper Protection thing. It might actually make a difference! Microsoft:. Sorry. Avoiding having your stuff encrypted by cybercriminals is a feature for E5 orgs.
Replying to @arekfurt
Jonas L Retweeted Jonas L
lol stop- tamper protection is a joke.... here is how to make it load another driverhttps://twitter.com/jonasLyk/status/1378143191279472644 …
Jonas L added,
Jonas L @jonasLyk
WIN32 paths inherently unreliable for linking a running process to the filename used to spawn it.
Letter based drive association are per LUID, per process and in no way static.
Thats part of why NT paths are used for loading drivers.
They have their own problems though. pic.twitter.com/SkTEJvXG9c
Show this thread
10:47 PM - 6 Aug 2021
1 reply
5 retweets
33 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.