Results 1 to 11 of 11
  1. #1
    xZaroxh's Avatar
    Join Date
    Sep 2019
    Gender
    male
    Posts
    1
    Reputation
    10
    Thanks
    4

    Bypassing newest BattlEye with Windows Kernel Explorer

    Hello,

    I recently found out that you can bypass/deactivate BattlEye AntiCheat while on a protected server with a free legit tool called Windows Kernel Explorer.
    Bypassing BattlEye Protection allows you to use Cheat Engine and similar programs (and probably some hacks) that inject code or change process memory in kernel mode.

    Tutorial:

    Step 1: Downloading Windows Kernel Explorer
    Since I cannot post links on here yet, you have to
    Google Windows Kernel Explorer.
    Click on first link (should be ******)
    Go to 'binaries' folder in repository
    Download WKE64.exe for 64-Bit System or WKE32.exe for 32-Bit-System
    Go to 'data' folder in repository
    Download 'WindowsKernelExplorer.dat'
    Move both files to new same folder on your system

    Step 2: Configuring & Running WKE
    Run 'WKE64.exe' or 'WKE32.exe' as admin
    It will create new folder called WKE64/32
    Close all WKE windows and/or browser windows that it has opened
    Move 'WindowsKernelExplorer.dat' in the new created folder WKE64/32
    Go to folder WKE64/32 and run 'WindowsKernelExplorer.exe' as admin
    It will tell you that current windows version is unsupported and it needs to download symbols to add support
    Just click on 'yes' and once finished loading 'ok'
    Please note that some AVs block the program from loading its kernel driver ("Unable to load driver"), if that's the case deactivate your AV.
    The program is now ready to use.

    Step 3: Bypassing / Deactivating BE Protection
    BattlEye uses kernel mode driver to watch Game process memory and starting/activity of (cheat-)programs

    First we need to suspend the BE kernel mode driver thread.
    Click button on top called Process
    Right-Click on System Process with PID 4 (should be first in list)
    Click on 'View Thread...'
    Click on Tab 'Module' (twice if needed) to sort by Module Path
    There should be something like 'C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys' first in list.
    Right-Click it and click on 'Suspend Thread'

    The BattlEye Kernel Driver thread is now suspended and we need to remove some of BE's kernel callbacks.

    Close the 'View Thread'-Window
    Click button on top called Kernel and select Callback & Notification
    Click on Tab 'Module' (twice if needed) to sort by Module Path
    There should be 5 entries on top with Module Path like 'C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys' (like above)
    Select (Ctrl-Click) ONLY!!! the entries with type CreateProcess, CreateThread & LoadImage (should be 3 in total)
    Right-Click on them and click 'Remove'.
    There should be two entries for BE left that you should leave there, or BE will detect "Corrupted Memory"

    That's it. Now BattlEye is unable to scan DayZ game memory, running and starting processes, and drivers on your system.
    You can now use Cheat Engine with all CE Kernel routines (found under Settings->Extra) enabled (works only that way, usermode BE protection is still active).


    Have Fun, Survivorz

  2. The Following 4 Users Say Thank You to xZaroxh For This Useful Post:

    eleonardo007 (10-14-2019),lol_1234 (09-17-2019),owlreed (03-02-2020),Razor_13 (06-10-2020)

  3. #2
    lol_1234's Avatar
    Join Date
    Dec 2015
    Gender
    female
    Posts
    4
    Reputation
    10
    Thanks
    2
    My Mood
    Amazed
    Works good.
    Thank you

  4. #3
    Adim2P's Avatar
    Join Date
    Feb 2019
    Gender
    male
    Location
    House
    Posts
    18
    Reputation
    10
    Thanks
    1
    My Mood
    Devilish
    nice this works

  5. #4
    DayZSupplyer's Avatar
    Join Date
    Mar 2016
    Gender
    male
    Posts
    8
    Reputation
    10
    Thanks
    1
    My Mood
    Amazed
    still working?

  6. #5
    ThFrkn's Avatar
    Join Date
    Nov 2019
    Gender
    male
    Posts
    10
    Reputation
    10
    Thanks
    0
    is this still working?

  7. #6
    berselon's Avatar
    Join Date
    Nov 2015
    Gender
    male
    Posts
    2
    Reputation
    10
    Thanks
    0
    now - does not work

  8. #7
    Robert R. Chance's Avatar
    Join Date
    Dec 2019
    Gender
    male
    Location
    USA
    Posts
    5
    Reputation
    10
    Thanks
    0
    Unfortunately, it doesn’t work either.

  9. #8
    America's Avatar
    Join Date
    Oct 2014
    Gender
    male
    Location
    The greatest country on earth
    Posts
    79
    Reputation
    10
    Thanks
    24
    My Mood
    Lurking
    This would be epic if it worked. Any updates?

  10. #9
    Tater Salad's Avatar
    Join Date
    Jan 2020
    Gender
    male
    Posts
    2
    Reputation
    10
    Thanks
    0
    Bump. Keen for that bypass.

  11. #10
    Ohsaewon's Avatar
    Join Date
    Oct 2018
    Gender
    male
    Posts
    286
    Reputation
    42
    Thanks
    24
    The enchanted mind predicts the expansion.

  12. #11
    komanlas's Avatar
    Join Date
    Sep 2012
    Gender
    male
    Posts
    15
    Reputation
    10
    Thanks
    0
    broken or work?

Similar Threads

  1. [Tutorial] [3.17.8.0]Bypass Battleye with Modules
    By AtiLion in forum Unturned Hacks & Cheats
    Replies: 14
    Last Post: 06-27-2017, 05:28 AM
  2. Newest bypass doesnt work with the chams
    By charlie6696 in forum Combat Arms Hacks & Cheats
    Replies: 8
    Last Post: 09-06-2008, 11:09 PM
  3. Help with windowed mode
    By Piercing Goblin in forum Combat Arms Hacks & Cheats
    Replies: 7
    Last Post: 08-05-2008, 05:16 PM
  4. how to i make a bypass in vb6 with the hack?
    By Oneirish in forum Visual Basic Programming
    Replies: 13
    Last Post: 03-31-2008, 12:53 PM
  5. Trading bypass for Hack with invisible.
    By wrasia in forum WarRock - International Hacks
    Replies: 12
    Last Post: 08-15-2007, 01:11 PM