Ground Level: x86 Architecture BasicsInstruction Set Architectures and the Operating SystemProtection RingsBridging the RingsKernel Mode: The Digital Wild WestThe Target: Windows Kernel ComponentsThe Win32 SubsystemWhat Are These APIs Anyway?The Concierge: NTDLL.DLLFunctionality by Committee: The Windows Executive (NTOSKRNL.EXE)The Windows Kernel (NTOSKRNL.EXE)Device DriversThe Windows Hardware Abstraction Layer (HAL)Kernel Driver ConceptsKernel-Mode Driver ArchitectureGross Anatomy: A Skeleton DriverWDF, KMDF, and UMDFKernel-Mode RootkitsWhat Are Kernel-Mode Rootkits?Challenges Faced by Kernel-Mode RootkitsMethods and TechniquesKernel-Mode Rootkit SamplesKlog by ClandestinyAFX by AphexFU and FUTo by Jamie Butler, Peter Silberman, and C.H.A.O.SShadow Walker by Sherri Sparks and Jamie ButlerHe4Hook by He4 TeamSebek by The Honeynet ProjectSummarySummary of Countermeasures