ISSUE DESCRIPTION HAS BEEN REWRITTEN BY MAINTAINER @jxy-s:
For the latest kernel support, ensure you are on the latest Canary build of System Informer:
Help > Check for updates > Canary > Check
This issue is for requesting support for new Windows kernel versions. The driver relies on specific data that must be updated and published to support new kernel versions. This data includes internal offsets within the operating system, which the driver uses to provide extended capabilities and system inspection. The data is signed using a cryptographic algorithm and verified by the driver before it is loaded. This signing process ensures that the data has been produced by the project maintainers and not by a third party, preventing potential misuse or abuse of the kernel driver.
To request support, please post a screenshot of the error dialog (see example above).
Out-of-date dynamic data does not prevent the driver from loading. If the machine is configured correctly, System Informer is treated as trusted and any features that do not rely on dynamic data will continue to function. If the machine configuration does not allow the driver to establish the trustworthiness of the System Informer process, access to the driver is further restricted.
When the machine is correctly configured but the dynamic data is out of date, System Informer enters Reduced Functionality mode. This is indicated in the title bar as ++ (RF):
To support Reduced Functionality mode, LSA protection must be enabled. Instructions for enabling LSA protection are provided by Microsoft here:
https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection#enable-lsa-protection-on-a-single-computer
LSA protection is enabled by default on modern versions of Windows and it is strongly recommended to leave it enabled.
If LSA protection is not enabled, up-to-date dynamic data is required for the driver to verify the trustworthiness of the System Informer process. In this configuration, if the dynamic data is out of date, an error is displayed and the title bar reflects a lower trust state (typically ~ (RF)). In this state, access to the kernel driver is restricted:
If the machine is not configured with LSA protection enabled, it must wait for updated dynamic data before full driver access can be restored.
Please note: Support for new kernel versions may be delayed for various reasons. Usually, Microsoft makes the necessary information public within 24 hours of a new kernel version being released. However, on rare occasions, this information may take days or even a week to appear. In some cases, Microsoft may not provide sufficient information, requiring more effort on our part to update the data. Additionally, delays may occur if the maintainers are occupied with other tasks. While we typically respond to new kernel versions within 48 hours of their release, there are times when it may take up to a week. We are working on automating this process to improve our response time.
We appreciate your efforts in requesting support for new kernel versions and ask for your patience while we work through the necessary updates.
ISSUE DESCRIPTION HAS BEEN REWRITTEN BY MAINTAINER @jxy-s:
For the latest kernel support, ensure you are on the latest Canary build of System Informer:
Help > Check for updates > Canary > CheckThis issue is for requesting support for new Windows kernel versions. The driver relies on specific data that must be updated and published to support new kernel versions. This data includes internal offsets within the operating system, which the driver uses to provide extended capabilities and system inspection. The data is signed using a cryptographic algorithm and verified by the driver before it is loaded. This signing process ensures that the data has been produced by the project maintainers and not by a third party, preventing potential misuse or abuse of the kernel driver.
To request support, please post a screenshot of the error dialog (see example above).
Out-of-date dynamic data does not prevent the driver from loading. If the machine is configured correctly, System Informer is treated as trusted and any features that do not rely on dynamic data will continue to function. If the machine configuration does not allow the driver to establish the trustworthiness of the System Informer process, access to the driver is further restricted.
When the machine is correctly configured but the dynamic data is out of date, System Informer enters Reduced Functionality mode. This is indicated in the title bar as
++ (RF):To support Reduced Functionality mode, LSA protection must be enabled. Instructions for enabling LSA protection are provided by Microsoft here:
https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection#enable-lsa-protection-on-a-single-computer
LSA protection is enabled by default on modern versions of Windows and it is strongly recommended to leave it enabled.
If LSA protection is not enabled, up-to-date dynamic data is required for the driver to verify the trustworthiness of the System Informer process. In this configuration, if the dynamic data is out of date, an error is displayed and the title bar reflects a lower trust state (typically
~ (RF)). In this state, access to the kernel driver is restricted:If the machine is not configured with LSA protection enabled, it must wait for updated dynamic data before full driver access can be restored.
Please note: Support for new kernel versions may be delayed for various reasons. Usually, Microsoft makes the necessary information public within 24 hours of a new kernel version being released. However, on rare occasions, this information may take days or even a week to appear. In some cases, Microsoft may not provide sufficient information, requiring more effort on our part to update the data. Additionally, delays may occur if the maintainers are occupied with other tasks. While we typically respond to new kernel versions within 48 hours of their release, there are times when it may take up to a week. We are working on automating this process to improve our response time.
We appreciate your efforts in requesting support for new kernel versions and ask for your patience while we work through the necessary updates.