Demystifying Modern Windows Rootkits
Offered By: Black Hat via YouTube
Course Description
Overview
Syllabus
Intro
What Is This Talk About?
Windows Rootkits: An Overview
Example: Treatment by Anti-Virus
Abuse Legitimate Drivers
Just Buy a Certificate!
Abuse Leaked Certificates
Beacon Out to a C2
Open a Port
Application Specific Hooking
Choosing a Communication Method
Abusing Legitimate Communication
Hooking the Windows Winsock Driver
Standard Methods of Intercepting Irps
Hook a Driver's Dispatch Function
Abusing the Network
Parsing Packets: Design
Parsing Packets: Pre-Processing
Parsing Packets: Processing
Parsing Packets: Dispatching
Packet Handlers: XorPacketHandler
Executing Commands: User-mode
Executing Commands: Kernel-mode
Introduction to Mini-Filters
Become a Mini-Filter
Hook a Mini-Filter: Code Hook
Example: Abusing a Mini-Filter
Taught by
Black Hat
Related Courses
Rootkits and Stealth Apps: Creating & Revealing 2.0 HACKINGUdemy CNIT 126: Practical Malware Analysis
CNIT - City College of San Francisco via Independent OPSEC and Personal Security Guide - Cybertalk Episode 7
HackerSploit via YouTube Investigating Malware Using Memory Forensics - A Practical Approach
Black Hat via YouTube The Advanced Threats Evolution- REsearchers Arm Race - Alex Matrosov - Ekoparty Security Conference - 2019
Ekoparty Security Conference via YouTube