
Bootkit for Windows Sandbox to disable DSE/PatchGuard.
Bootkit tested on Windows Sandbox to patch ntoskrnl.exe and disable DSE/PatchGuard. There is a blog post going into more detail about the implementation.
Installer.exeNote: (parts of) the release might be detected as a virus by Windows Defender. This is a false positive, so you might need to add an exclusion.
If you run into issues getting things to work on Windows Sandbox make sure you try with development mode enabled (CmDiag DevelopmentMode -On). On Windows 11 there have been reports of the changes not being applied to the sandbox without it.
You can run SandbotBootkit.efi on real hardware or a VM too (although you might as well use EfiGuard in that case). To do so you attach a new (virtual) disk (formatted as FAT32) and copy SandboxBootkit.efi to \EFI\Boot\bootx64.efi. Then change the boot order to boot from your new disk first. The relevant functionality is implemented in the LoadBootManager function.
SandboxBootkit.sln to build the projectInstaller project on how to install the bootkitNote: During development it's easiest to enable development mode. Without it you won't be able to write to the BaseLayer.