WCU / Cybersecurity
~/CSC 471/Class 09
CSC 471 · Class 09

Rootkits and Stealth

25 knowledge points. Work through them in order, or jump to any topic.

//

Knowledge Points

01What Is a Rootkit? 02The Goal of Stealth 03Rings: Ring 3 vs Ring 0 04User-Mode vs Kernel-Mode Rootkits 05User Mode: Hooking the Enumeration APIs 06User Mode (Linux): LD_PRELOAD 07User Mode (Windows): IAT and Inline Hooking 08Windows Kernel: SSDT Hooking 09SSDT Redirect (Diagram) 10Windows Kernel: DKOM 11Windows Kernel: IRP Hooking 12Linux: Loadable Kernel Module Rootkits 13Linux: Hiding the Module 14Linux: Hooking System Calls 15Linux: Privilege Escalation via cred 16Going Below the OS: Bootkits and UEFI Implants 17Case Study: Stuxnet (2010) 18Stuxnet: The Rootkit Layer 19Stuxnet: The First PLC Rootkit 20Stuxnet: Lessons 21Detection: Cross-View (the core idea) 22Detection: Memory Forensics and Hardening 23Detection: The Arms Race 24Lab 5: Build a Linux LKM Rootkit 25Summary