I am currently attempting to reverse engineer some malware that creates and runs a kernel mode driver. It has many, many anti-debug techniques but the Scylla Hide plugin is able to bypass them all. Is there anyway to make those changes permanent?
The end goal is to run windbg so I can see the service that creates and runs the kernel mode driver but the malware is currently detecting the presence of windbg.
Thanks in advance!