Kn-Live-Dbg v0.0.7 is out.
See cheats unpacking, malware injecting, drivers loading — at the moment the kernel sees them. v0.0.7 makes KnLiveDbg a PPL Antimalware consumer of Microsoft-Windows-Threat-Intelligence, the ETW provider EDRs depend on, and matches cross-process activity by the VICTIM, not just the attacker.
→ "Cheat Engine RWX-allocates into notepad → caught by /name notepad.exe"
→ "Live tail of AllocVM, ProtectVM, WriteVM, MapView, SetThreadContext, QueueUserAPC"
→ "Forensic JSONL keeps every event. Detonate, walk away, jq later."
Adds set-ppl-antimalware (PPL self-elevation via driver write to _EPROCESS.Protection) and !ti (live TI subscriber:
TDH decoded, 1M ring, rotated log, target-side matching).
When EDRs see it, you see it.
repo:
github.com/kernullist/kn-liv…
#WindowsKernel #AntiCheat #BYOVD #DFIR