2025-02-16 (Anti-)Anti-Rootkit Techniques - Part III: Hijacking Pointers Anti-RootkitData Pointer SwapKernelRootkitWindows Windows Kernel Rootkits In Part II of this series, we looked at how we could be hiding our rootkit’s thread from the eyes of a vigilant anti-roo
2024-09-19 (Anti-)Anti-Rootkit Techniques - Part II: Stomped Drivers and Hidden Threads Anti-RootkitKernelPspCidTableRootkitWindows Windows Kernel Rootkits At the end of Part I of this Series, we ended up with a small anti-rootkit driver, that was able to detect malicious dri
2024-03-23 (Anti-)Anti-Rootkit Techniques - Part I: UnKovering mapped rootkits Anti-RootkitKernelManual MappingRootkitWindows Windows Kernel Rootkits While some blog posts exist that talk about developing offensive drivers and rootkits, the only ones that I found, which