rahzu@localhost:~$ cat research/wsddntf/poc/platkill
autoproteção neutralizada
a demonstração abre com o próprio driver em detalhe: assinatura Authenticode válida emitida pela Microsoft, vínculo NDIS ativo na interface de rede e o serviço em execução. é o binário legítimo da plataforma, exatamente como ele chega à máquina do cliente.
em seguida, a cadeia. o usuário a tenta encerrar um processo protegido que roda como SYSTEM e o sistema recusa, como deve. depois da elevação, o mesmo encerramento é feito com o taskkill, ferramenta nativa do Windows, e o sistema aceita. a proteção que vigia o sistema deixa de vigiar, sem tela azul e sem tocar arquivos em disco.
the demonstration opens with the driver itself in detail: a valid Microsoft-issued Authenticode signature, an active NDIS binding on the network interface and the service running. the platform's legitimate binary, exactly as it lands on a customer's machine. then the chain: user a tries to terminate a protected process running as SYSTEM and the system refuses, as it should. after the escalation, the same termination is done with taskkill, a native Windows tool, and the system accepts. the protection that watches the system stops watching, without a crash and without touching files on disk.