You are a 100% Right i did a mistake for not looking it from a Developer Point of viewI understand you concern and it is perfectly valid. But also, we need to look at it from a developer point of view. You think that relatively small set of actions will be easy to implement, a little bit of code, a little bit of graceful error handling and job done.
But in reality, when you start writing this “little bit of code” there are tens of little and not so little things coming up.
It could be done for a few reasons:
To find out whether a cheat has compromised PatchGuard
To redirect calls cheats can make to its own anti-cheat system (similar to how AV behavioural blocking works).
To scan for Virtual Maxhine
These practices are highly invasive and can lead to system instability. It’s sad to see a gaming platform going that far.
But again, this is all facilitated by legitimate operations Mictosoft allows, no attacks are used in the process and it will be very difficult (even when damage is caused) to prove that this damage is caused intentionally.
In Essence, yes. This is one piece of invasive, intrusive and nosy junkware that gains far more privileges than it needs.
But to prove it is illegal, the @bazang suggestion is the best one and it’s very costly.
I dont think so i am trying to code a WDM project called Regfilter and i would never think that Small set of actions will be Easy to Implement Of course not
your 3 points
It could be done for a few reasons:
To find out whether a cheat has compromised PatchGuard
To redirect calls cheats can make to its own anti-cheat system (similar to how AV behavioural blocking works).
To scan for Virtual Maxhine
are correct and You are Damn right
Many cheats use drivers to bypass the Anti-Cheat which Compromises the OS Overall security wise and Stability Wise 100% True
now yes you also stated a correct thing which is
These practices are highly invasive and can lead to system instability. It’s sad to see a gaming platform going that far.
True no need to follow these Practices in general but they do it anyway and the fact that most people know about it and they know what it is Capable of but they ignore it
drives Me nuts
Yes the Decompiled code shows it has DigiCert and a .pem file
And his Suggestion is good but i submitted the report to EFF like 5 days Ago
No response until now i contacted also Louis Rossmann Cisco Talos CISA FTC Troy Hunt Journalists with Cyber security background and none Replied
which also drives me nuts i just wanted to share awareness about this
Because it seems illegal and Malware Based Driver
and also it runs without admin prompt which also Solidifies that Microsoft helped making the driver because they know windows
More than anyone else on the planet
But what else do you Suggest should i do ?
Because i am always thinking what should i do to spread awareness about this
Thank you So much for your Assistance

