2025-02-16 (Anti-)Anti-Rootkit Techniques - Part III: Hijacking Pointers Anti-RootkitData Pointer SwapKernelRootkitWindows Windows Kernel Rootkits In Part II of this series, we looked at how we could be hiding our rootkit’s thread from the eyes of a vigilant anti-roo
2024-09-19 (Anti-)Anti-Rootkit Techniques - Part II: Stomped Drivers and Hidden Threads Anti-RootkitKernelPspCidTableRootkitWindows Windows Kernel Rootkits At the end of Part I of this Series, we ended up with a small anti-rootkit driver, that was able to detect malicious dri
2024-03-23 (Anti-)Anti-Rootkit Techniques - Part I: UnKovering mapped rootkits Anti-RootkitKernelManual MappingRootkitWindows Windows Kernel Rootkits While some blog posts exist that talk about developing offensive drivers and rootkits, the only ones that I found, which
2024-02-25 Keylogging in the Windows kernel with undocumented data structures KernelKeyloggingRootkitWindowsgafAsyncKeyState Windows Kernel Rootkits If you are into rootkits and offensive windows kernel driver development, you have probably watched the talk Close Encou