Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Demystifying Modern Windows Rootkits

Black Hat via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk walks through writing a Windows kernel rootkit, from a basic driver to techniques for loading rootkit code, abusing legitimate drivers, intercepting user-mode network traffic, executing commands, and concealing filesystem traces. It also discusses detection vectors and the limitations of kernel-mode malware.

Syllabus

Intro
What Is This Talk About?
Windows Rootkits: An Overview
Example: Treatment by Anti-Virus
Abuse Legitimate Drivers
Just Buy a Certificate!
Abuse Leaked Certificates
Beacon Out to a C2
Open a Port
Application Specific Hooking
Choosing a Communication Method
Abusing Legitimate Communication
Hooking the Windows Winsock Driver
Standard Methods of Intercepting Irps
Hook a Driver's Dispatch Function
Abusing the Network
Parsing Packets: Design
Parsing Packets: Pre-Processing
Parsing Packets: Processing
Parsing Packets: Dispatching
Packet Handlers: XorPacketHandler
Executing Commands: User-mode
Executing Commands: Kernel-mode
Introduction to Mini-Filters
Become a Mini-Filter
Hook a Mini-Filter: Code Hook
Example: Abusing a Mini-Filter

Taught by

Black Hat

Reviews

Start your review of Demystifying Modern Windows Rootkits

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.