Chaos-Rootkit: Internals Explained
This write-up covers the internals of Chaos-Rootkit, a Ring-0 Windows rootkit I wrote to better understand kernel internals and rootkit techniques. Fun fact: Many parts of this rootkit were written during train rides 😄! The following list summarizes the implemented capabilities. Each item is explained in later sections. * Hide process: This