Fixed HWBGuard (Silent) excessive alert reporting, now limited to max 2 alerts per process.
* Beware this build is signed with a new code-signing certificate by Sophos LTD, this might take some 3rd party vendors to have "trust" issues as it's a rather fresh certificate.
Build 975 (2023-12-14)
Added HWBGuard (Silent), A technique heavily used by red-teams to bypass Syscall protections is to set a HardwareBreakPoint, we now detect these breakpoints
Added New Process Protection panel for Risk Reduction
Added RDPGuard Icon under Risk Reduction button
Added SendKeyGuard
Fixed BSOD in StickyKeys
Fixed Driver BSOD under specific circumstances
Fixed KernelTrap compatibility issues with Kaspersky and GenshinImpact
Fixed Lockdown Bypass when loading files over UNC paths
Improved AMSIGuard
Improved APC Game detection
Improved Bitdefender Compatibility
Improved CiGuard
Improved CookieGuard
Improved CryptoGuard5
Improved DrWeb Compatibility CallerCheck/SysCall
Improved DrWeb Compatibility CallerCheck/SysCall
Improved HeapHeapProtect Cobalt Strike detection
Improved HeapHeapProtect prevents Powershell scripts from patching AMSI for bypass
Improved HollowProcess
Improved KeyboardGuard u.a. compatibility with ESET protected browsers, Windows search
Improved Lockdown Now allows WMIC GET 'only' commands without interference
Improved PrivGuard
Improved StackPivot
Removed ReflectiveDLL As it has become obsolete in it's current implementation
Several other changes under the hood
* Beware this build is signed with a new code-signing certificate by Sophos LTD, this might take some 3rd party vendors to have "trust" issues as it's a rather fresh certificate.
当然HitmanPro也更新了 Build 330 (2023-11-02)
FIXED: Delete failed for Firefox cookies.
FIXED: Close browsers cookie dialog logic.
ADDED: Detection of Chrome Sxs and Chrome Dev cookies.
ADDED: Detection of Chrome cookies from different profiles.
ADDED: Detection for several Firefox based browser cookies.
UPDATED: Edge Chromium icon.
KNOWN ISSUE(S): ARM64 browser processes are not closed before scan (yet).