WCU / Cybersecurity
Home
CSC 471
CSC 472
Search
/
~
/
CSC 471
/
Class 09
CSC 471 · Class 09
Rootkits and Stealth
25 knowledge points. Work through them in order, or jump to any topic.
//
Knowledge Points
01
What Is a Rootkit?
→
02
The Goal of Stealth
→
03
Rings: Ring 3 vs Ring 0
→
04
User-Mode vs Kernel-Mode Rootkits
→
05
User Mode: Hooking the Enumeration APIs
→
06
User Mode (Linux): LD_PRELOAD
→
07
User Mode (Windows): IAT and Inline Hooking
→
08
Windows Kernel: SSDT Hooking
→
09
SSDT Redirect (Diagram)
→
10
Windows Kernel: DKOM
→
11
Windows Kernel: IRP Hooking
→
12
Linux: Loadable Kernel Module Rootkits
→
13
Linux: Hiding the Module
→
14
Linux: Hooking System Calls
→
15
Linux: Privilege Escalation via cred
→
16
Going Below the OS: Bootkits and UEFI Implants
→
17
Case Study: Stuxnet (2010)
→
18
Stuxnet: The Rootkit Layer
→
19
Stuxnet: The First PLC Rootkit
→
20
Stuxnet: Lessons
→
21
Detection: Cross-View (the core idea)
→
22
Detection: Memory Forensics and Hardening
→
23
Detection: The Arms Race
→
24
Lab 5: Build a Linux LKM Rootkit
→
25
Summary
→