Transcription of Defeating x64 - cdn1.esetstatic.com
{{id}} {{{paragraph}}}
Defeating x64: Modern Trends of kernel -Mode Rootkits Aleksandr Matrosov Eugene Rodionov Who we are? Malware researchers at ESET. - rootkits analysis - development of cleaning tools - tracking new rootkit techniques - investigation of cybercrime groups Agenda Evolution of payloads and rootkits Bypassing code integrity checks attacking windows Bootloader Modern Bootkit details: Win64/Olmarik Win64/Rovnix How to debug bootkit with Bochs emulator HiddenFsReader as a forensic tool Evolution of Rootkits Evolution of Rootkit Installation exploit payload dropper rootkit Evolution of Rootkit Installation Malicious Exploit Bypass Escape Web-site Vulnerability ASLR/DEP Sandbox Execute Download Escalate Payload Rootkit Local Privilege kernel -Mode Exploit Install Rootkit Ev
Attacking Windows Bootloader ... ldr32 reads TDL4’s kernel-mode driver from hidden file system and maps it into kernel-mode address space ldr64 implementation of ldr32 module functionality for 64-bit OS
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}
Metasploit Lab: Attacking Windows XP, Windows, Kernel, Observing Linux Behavior, Attacking, A Guide to Kernel, One Software Bypass of Windows 8, Window s, Internals, Attacking the Windows, Over ASLR: Attacking Branch Predictors to Bypass, Attacking Hypervisors via Firmware and Hardware, KQguard: Binary-Centric Defense against Kernel