Is an ELAM driver not tailored to do only the things @GenV indicated in his post?
Basically, ELAM is used to allow/block other boot drivers by checking with malicious digital signatures db in registry, then it unloads and "passes the torch" to regular protection driver (its MS recommendation for the ELAM/AM drivers). I think it couldn't be used for anything else.![]()
ELAM Driver Requirements - Windows drivers
Driver installation must use existing tools for online and offline installation, registering a driver through typical INF processing.learn.microsoft.com
MS has pretty strict requirements for ELAM driver performance:
View attachment 291940
Also, it stores certificates required for AM service to start as PPL-AM process.
![]()
Protecting anti-malware services - Win32 apps
Learn about protecting anti-malware (AM) user mode services and how you can opt to include this feature in your anti-malware service.learn.microsoft.com

