← Back to driver explorer
Driver intelligenceVulnerableVerified

AToolsKrnl64.sys

Antiy ATool AToolsKrnl64.sys from the reported 2.0.26.819 package exposes process termination through IOCTL 0x99000050. Its caller check validates an Antiy-signed executable on disk and caches the accepted process, but does not verify the integrity of the running client. A modified genuine client can therefore pass this check and request termination of caller-selected processes. Static analysis of this sample confirms a world-readable device and a kernel-mode target-open path that does not require the caller to already hold termination rights. The termination path rejects targets with a nonzero driver-defined protection/state byte. The public demonstration terminates only a self-created ordinary child; protected-process and EDR termination are not established.

UUID / 643b121c-f883-5699-a032-f07c1e9eecfdADDED / 2026-09-23AUTHOR / Xusheng Li

Known samples 1

0 recorded TRUE · 0 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.

AToolsKrnl64.sysSample 1 · HVCI unknown
MD5
f0a5d14e0a8acea507ef9a694661e544
SHA1
8f18c4c157b4078669364c081068fc2bb271c12b
SHA256
f85af685660a28e3cd18e2c9ef6b1fbb440ae0c5934e625e8a055e1f158c3e56
Imphash
79724a023a31b15116d696a24877176a
Authentihash MD5
fcf3fe21b796b21967ac2f9c292c22d1
Authentihash SHA1
c5acaa2a55817ea99875a159c761530c8aa16a0d
Authentihash SHA256
613d60ec08d1383b38d0c6c01b870712864865a70f13677dee7cc1270caacab1
Machine
AMD64
Version
2.0.26.819
Publisher
Antiy Labs

Research & references

Acknowledgement: Xusheng Li @xusheng6