might wanna blacklist this driver:
BEDaisy.sys, MD56917ef5d483ed30be14f8085eaef521b
can be used to read/write your protected games.. in short: bedaisy offers handle elevation to vm read/write...
githacks.org/xerox/badeye
Conversation
Imagine not encrypting IOCTLs as an anticheat driver in 2020 holy shit, even FaceIT and ESL do that.
2
2
Validation is precisely what I meant. Don't accept irp data for custom driver specific ioctls without some sort of "knock" or hash or secret tacked on.


