When reverse engineering malware, how to make scylla hide changes permanent

Viewed 99

I am currently attempting to reverse engineer some malware that creates and runs a kernel mode driver. It has many, many anti-debug techniques but the Scylla Hide plugin is able to bypass them all. Is there anyway to make those changes permanent?

The end goal is to run windbg so I can see the service that creates and runs the kernel mode driver but the malware is currently detecting the presence of windbg.

Thanks in advance!

0 Answers
Related