truesight.sys
This is a C# AV/EDR Killer using Rogue Anti-Malware Driver 3.3. This driver is not present in the loldrivers or Windows blocklist at the time of this writing. The only reason I'm making this public is because the company has already published a fix in version 3.4, and Microsoft will likely block this driver soon. This driver can be used in Windows 23H2 with HVCI enabled, loldrivers blocklist, or WDAC enabled. HVCI is designed to ensure the integrity of code executed in the kernel, but it cannot protect against all possible vulnerabilities or actions that can be performed through drivers or system interfaces.
Known samples 2
0 recorded TRUE · 1 recorded FALSE · 1 unknown for loading despite HVCI. Results apply to individual samples.
TruesightSample 1 · HVCI FALSE
- MD5
f53fa44c7b591a2be105344790543369- SHA1
363068731e87bcee19ad5cb802e14f9248465d31- SHA256
bfc2ef3b404294fe2fa05a8b71c7f786b58519175b7202a69fe30f45e607ff1c- Imphash
b95bc1a99081d695b1c0b37b90a4a0be- Authentihash MD5
7ac40b0bee0d9b6e84d58d567e82e736- Authentihash SHA1
13c6de4203098a8017a0bd4c4da98f6d547482bb- Authentihash SHA256
891ad430e7f1d58ef85b437505a6016fa99a72abcfd4734476efc5fc1fcd1cba- Machine
- AMD64
- Version
- 3.3.0
- Publisher
- Adlice Software
TruesightSample 2 · HVCI unknown
- MD5
531121e7ed50084b493a69f8f8a7a927- SHA1
28c37b1c0af4a2a75a9662544fb3181a71c45dd2- SHA256
bfbfcb7cae421739163e7630865009d3197f587265e9e5797142d93e1b72b191- Imphash
ba0a77ce9e566f704a1655d999d41048- Authentihash MD5
e500e54b63b017a00fddcc37a6d47a90- Authentihash SHA1
79573b1d088101b2ebea80da1ab2dbb83725336a- Authentihash SHA256
13a64ee87e5e407cb592026b7d0bed501a2ae5bfaa33312d89e0f62fe4278828- Machine
- AMD64
- Version
- 1.0.3
- Publisher
- Adlice Software
Recorded command
sc.exe create truesight.sys binPath=C:\windows\temp\truesight.sys type=kernel && sc.exe start truesight.sysElevate privileges · Privileges: kernel · OS: Windows 11

