Title: How to / Terminology in the software
04/01/2022 23:39 - 57 days 13 hours 2 minutes
Kernel mode (KM)
Kernel driver interface (KDI)

How to use the handle elevation DKOM feature?

1) KDI->Initialize
2) KDI->Load the driver
3) Open the process in the tool whose handle you want to elevate
4) Hover over the process or select a process in HEX DEREF and then right-click to elevate the handle

If you use HEX DEREF to scan process memory that is protected by a kernel level anti-cheat. Make sure you you disable KM:

Edit->Settings->Memory viewer->Use the kernel driver to read or write an arbitrary kernel or user process memory

Every time when you reboot your computer. Before you can browse the kernel memory. You must repeat steps 1 and 2.

