Earlier quoted context omitted.
Can't wait to find out what China hid in Riot's Vanguard rootkit for all their games. It's 100% a conspiracy theory, but nobody can convince me it's perfectly clean, or if it is, that there isn't an easy way to add some power to it quietly.
The vanguard drivers are signed by Microsoft, the procedure for which includes a safety audit by Microsoft. The driver is just what the developers say it is (as with all other anti-cheat). It provides an untempered interface for the userland anti-cheat to use to get info from the kernel. Because modern cheats tend to alter the output of kernel syscalls by running in the kernel themselves. I really don't see why anyon…
Did the crowdstrike driver get the same audit?