CyberLock 9.0

  • Thread starter Thread starter danb
  • Start date Start date
  • Featured
Just any random keylogger/file. What i think is, do i have to have a keylogger installed, or is it enough with CL.
The only way for me to answer this question correctly is for you to let me know exactly which keylogger you are talking about. If you want a wild guess without knowing the specific file, I can say in general, if the keylogger is a legitimate app that is signed and installed in a legitimate location, then CyberLock is not supposed to block it. But if it is a keylogger that is malware, then CyberLock is supposed to block it.

I personally do not see any reason to have a keylogger installed, but then again, that might not be a bad additional layer if you think you think someone is logging into your computer without your permission.
 
@pxxb1
Hello, I don't want to go off-topic but if you're concerned about a potential malware keylogger and to integrate the protection already offered by CyberLock / Sirius GPT I suggest the anti-keylogger KeyScrambler. The Personal Edition is free of charge and works in 80+ web browsers. Compare Editions – KeyScrambler by QFX Software Corp. Here it is the MT thread Serious Discussion - KeyScrambler v.3.16 - 3.18 if you have questions about it and here it is how it works Features – KeyScrambler by QFX Software Corp.
 
Last edited:
@pxxb1
Hello, I don't want to go off-topic but if you're concerned about a potential malware keylogger and to integrate the protection already offered by CyberLock / Sirius GPT I suggest the anti-keylogger KeyScrambler. The Personal Edition is free of charge and works in 80+ web browsers. Compare Editions – KeyScrambler by QFX Software Corp. Here it is the MT thread Serious Discussion - KeyScrambler v.3.16 - 3.18 if you have questions about it.

I am trying it out, hence my questions about CL. I am trying to make a decision.
 
  • Like
Reactions: danb and Sorrento
Hey guys! The new driver implementation went better than expected, so it is ready to test!

Please do not install this version on a production / daily driver system quite yet. I have tested on 2 bare metal computers and one VM and it is working great, but until a few other people test this beta version, it might be a good idea to hold off installing on a production / daily driver system.

The driver has been completely rewritten and now includes full BypassIO support. I’ve been running it for 2–3 months with a test signature while waiting for Microsoft to sign it, with Driver Verifier enabled the entire time. There hasn’t been a single Verifier violation or stability issue, so I think we are good to go.

CyberLock 9.12beta
SHA-256: 1aa7610dd62bba2a4ab0ad448a55300a585ad8fdef489ca6e4d0bc805512efaf

Please post your results, good or bad, thank you!
since 9.12 beta has a new driver, will it install correctly over 9.10 or should I uninstall 9.10 and then install 9.12 beta :unsure:
 
Last edited:
@pxxb1
Hello, I don't want to go off-topic but if you're concerned about a potential malware keylogger and to integrate the protection already offered by CyberLock / Sirius GPT I suggest the anti-keylogger KeyScrambler. The Personal Edition is free of charge and works in 80+ web browsers. Compare Editions – KeyScrambler by QFX Software Corp. Here it is the MT thread Serious Discussion - KeyScrambler v.3.16 - 3.18 if you have questions about it and here it is how it works Features – KeyScrambler by QFX Software Corp.
KeyScrambler is garbage. Has been since it's release. And I own a PRO license. It's better not to get a keylogger in the first place than rely on KS to protect you after infection..
 
since 9.12 beta has a new driver, will it install correctly over 9.10 or should I uninstall 9.10 and then install 9.12 beta :unsure:
Ooops, I forgot to mention this... yes, please install the new version over the top of the old version, that way we can see if the driver upgrade works properly. Thank you!
 
Ooops, I forgot to mention this... yes, please install the new version over the top of the old version, that way we can see if the driver upgrade works properly. Thank you!
@danb yes 9.12b installed ok here, I did leave 9.10 running but set to "disable/install" and looks good so far. no problems seen so far...
 
Hey Dan. May I ask when you are planning to roll out the 9.12 update for all users? 👀
Pretty soon... I am just taking my time because the same driver is going to be implemented into DefenderUI Pro, WDAC Lockdown and SiriusGPT, so I wanted to make 100% sure there were zero bugs before we roll all of them out. So far there has been zero issues, so I think we are good to go. Thank you!
 
What if I tried it out as soon as I've posted all my videos? :p :cool:
Sure, that would be super cool, thank you! Be super hard on it... give it hell ;). It's funny, I was chatting with Claude a couple of weeks ago and I said something like "The CyberLock Sirius verdict for non-compiled malware, LOLBins, command lines, etc. is approaching 100% efficacy." Claude is a grumpy old man now and he is always pushing back... he did not used to be this way, I think Anthropic over corrected. Anyway, Claude pushed back and said something like "Dan, you are seriously overstating the efficacy for for non-compiled malware, LOLBins, command lines, etc." And I said "Oh yeah, let's test.". So Claude sent me 100 command lines / exploits... 50 were malicious and 50 safe. I tested the first 10 and sent the results to Claude and scored 100%. It took like an hour to test, so I told Claude to send me the toughest ones next... and to make a long story short, I asked Claude to rate Sirius on a scale from 1-10, and Claude gave us an 11 ;).

Anyway, is it just me, or is Claude a grumpy old man now? He used to be extremely agreeable, but I think when Anthropic fixed that, they over compensated. He pushes back on every single thing I say now ;).
 
Yeah, while Claude is a grumpy old man, I think of Grok as a know it all 20 year old that sometimes actually knows something valuable ;). I was the same way when I was 20... I just hope I do not turn into a grumpy old man ;).
 
Yeah, while Claude is a grumpy old man, I think of Grok as a know it all 20 year old that sometimes actually knows something valuable ;). I was the same way when I was 20... I just hope I do not turn into a grumpy old man ;).
The words you are trying to find with regards to Claude is virtue signalling and woke garbage. Putting massive guardrails people just move to Chinese AI which has less.
 
  • Like
Reactions: Sorrento and danb
Could you elaborate on that ?
What more do you need? They are American but object to the military using it. They constantly put in guardrails that are not based on science or data but on woke morals.

People just move to Chinese or open source models, banning or making things illegal NEVER stops people they just move to the platform that offers them what they want.

Everyone is using AI for hacking, just because you 'virtue signal' and ban it doesn't stop it from happening. Technology is agnostic with zero political agenda, don't turn into one.

And what good are the guardrails when your own AI agents hack other companies?

Also you think the Chinese or North Koreans or Russians are not using AI for weapons development including developing new chemical weapons? Please.....
 
What more do you need? They are American but object to the military using it. They constantly put in guardrails that are not based on science or data but on woke morals.

People just move to Chinese or open source models, banning or making things illegal NEVER stops people they just move to the platform that offers them what they want.

Everyone is using AI for hacking, just because you 'virtue signal' and ban it doesn't stop it from happening. Technology is agnostic with zero political agenda, don't turn into one.

And what good are the guardrails when your own AI agents hack other companies?

Also you think the Chinese or North Koreans or Russians are not using AI for weapons development including developing new chemical weapons? Please.....
A lot of things are either way too far right or left these days. From what I understand, Anthropic believes the military could benefit greatly from Claude, but they did not want their technology used for mass domestic surveillance or for fully autonomous weapons that can select and engage targets without a human in the loop. I personally believe keeping a human in the loop is vital as well.

And honestly, that is one of the reasons I am extremely happy with the way CyberLock's AI implementation ultimately evolved. It keeps the human in the loop at the point where it matters most: the execution decision.

This was not something I sat down one day and "invented" as a grand design. It just gradually formed over many years as CyberLock evolved.

Ironically, that is also a big part of why CyberLock fits so perfectly into the emerging Agentic SOC model. AI can analyze, reason, investigate and recommend actions, while CyberLock provides a controlled execution layer that keeps consequential endpoint decisions governed rather than simply handing unrestricted control to an autonomous agent.
 
Hey Guys!

There was a small bug in the driver .inf file that made it so 9.12 would not install on Windows Server. This bug has been fixed in this version.

CyberLock 9.13beta
SHA-256: edb8d3274f12b1a2e4ebcffba04344c2a142c95064bd3c7c83109bcf7254c1fa

We should probably give it another week or so, and then we will update all of the drivers in all of the products.

You can just install over the top of 9.10 or 9.12.


Thank you guys!

Dan
 
Hey Dan,

Ran into something on CyberLock 9.13 (Windows 11 Pro 26200, running next to Windows Defender + WHHLight) Smart mode, Aggressive, Smart Firewall on Recommended.

I've been using an AI (Claude Code) that fires off a ton of short-lived Git Bash processes in quick succession. Git's bash.exe isn't signed, so nothing matches the whitelist snapshot and every single spawn goes the full cloud route (VoodooAi + WhitelistCloud). Under that burst the service just can't keep up - launches were hanging for about two minutes each, and the machine basically became unusable while it churned.

Digging into the logs is where it got interesting. When the decision path backs up, the driver eventually gives up and lets the process through unevaluated:

[ERROR] HandleSingleProcess: process decision timed out after 122000 ms; replying fail-open to match driver timeout policy.
[ERROR] HandleSingleProcess: Failed to reply to driver (0x801F0020)

I counted 8 of those timeout/fail-open pairs inside about a 90-second window. Any workload that spawns lots of distinct unsigned processes fast should hit it: build tools, git hooks, interpreters shelling out, that kind of thing. A quick loop of 10-20 rapid unsigned launches was enough for me.

The part that made me raise an eyebrow is that the timeout fails OPEN. So a flood of process launches, mine were harmless, but they wouldn't have to be, opens a window where new processes get allowed without any evaluation at all. I keep thinking that for a default-deny product you'd want it to fail closed (block, or hold and retry) rather than wave things through when it's overwhelmed. Defender is still there as a backstop on my end, but the gate going open under load feels like something worth locking down.

For what it's worth, I did get my latency under control with a rule: an Allow rule, type Folder, C:\Program Files\Git\, applied in ON/OFF/AUTOPILOT, with all three file-insight checks (Digital Signature / VoodooAi / WhitelistCloud) turned off, and "Override Custom Folders Settings" on. The log shows the override doing exactly what I hoped:

[INFO] Process blocked by Custom Folders: c:\program files\git\bin\bash.exe
[INFO] Process allowed by Allow Rule: c:\program files\git\bin\bash.exe

After that, 10 back-to-back bash.exe launches ran in about 1.5s (~150ms each) instead of stalling for two minutes, and the timeouts stopped completely. Obviously that's a workaround for my case, not a fix for the fail-open itself.

So mostly I wanted to flag it, plus a few honest questions:

- Is the 122,000 ms fail-open deliberate? Could saturation fail closed instead so the gate can't be forced open by sheer volume?
- Any chance the service could remember a repeated identical unsigned image locally (a per-session decision cache) so it's not re querying the cloud on every spawn in Smart mode?
- Would a bounded or parallel decision queue help, so a burst of one process type doesn't block everything else?

Glad to send over the full DeveloperServiceLog / DeveloperLog with timestamps if that's useful. Thanks.