将服务注册为受保护的服务

Register service as protected service

我们正在为 Windows 开发安全套件。我们希望我们的流程像 Kaspersky 或 Avast 的流程一样不会被杀死。在网上浏览时,我遇到了 Windows 受保护的服务。

https://msdn.microsoft.com/en-us/library/windows/desktop/dn313124%28v=vs.85%29.aspx?f=255&MSPPError=-2147217396

如何将我的产品注册为 windows 受保护服务?

或者此服务是否仅适用于反恶意软件产品?它对安全套件的可用性如何,它可以执行 USB 设备管理、数据保护和类似的东西?

您需要编写 ELAM(早期启动反恶意软件)驱动程序才能创建受保护的服务。

Each driver .sys file must be code signed by Microsoft, using a special certificate indicating that it is an Early Launch AM Driver.

Antimalware Vendor Participation Requirements:

Microsoft requires that Early Launch Antimalware vendors either be members of the Microsoft Virus Initiative (MVI) or pre-approved members of the Virus Information Alliance (VIA). This membership ensures that the vendors are active antimalware community participants with a positive industry reputation. Please reach out to mvi@microsoft.com if you have questions about ELAM driver signing or becoming a pre-approved VIA member.