WCU / Cybersecurity
~/CSC 471/Class 09
CSC 471 · Class 09

Rootkits and Stealth

25 knowledge points. Work through them in order, or jump to any topic.

//

Knowledge Points

01What Is a Rootkit? → 02The Goal of Stealth → 03Rings: Ring 3 vs Ring 0 → 04User-Mode vs Kernel-Mode Rootkits → 05User Mode: Hooking the Enumeration APIs → 06User Mode (Linux): LD_PRELOAD → 07User Mode (Windows): IAT and Inline Hooking → 08Windows Kernel: SSDT Hooking → 09SSDT Redirect (Diagram) → 10Windows Kernel: DKOM → 11Windows Kernel: IRP Hooking → 12Linux: Loadable Kernel Module Rootkits → 13Linux: Hiding the Module → 14Linux: Hooking System Calls → 15Linux: Privilege Escalation via cred → 16Going Below the OS: Bootkits and UEFI Implants → 17Case Study: Stuxnet (2010) → 18Stuxnet: The Rootkit Layer → 19Stuxnet: The First PLC Rootkit → 20Stuxnet: Lessons → 21Detection: Cross-View (the core idea) → 22Detection: Memory Forensics and Hardening → 23Detection: The Arms Race → 24Lab 5: Build a Linux LKM Rootkit → 25Summary →