Skip to Content
Mastering Malware Analysis - Second Edition
book

Mastering Malware Analysis - Second Edition

by Alexey Kleymenov, Amr Thabet
September 2022
Beginner
572 pages
14h 5m
English
Packt Publishing
Content preview from Mastering Malware Analysis - Second Edition

7

Understanding Kernel-Mode Rootkits

In this chapter, we are going to dig deeper into the Windows kernel and its internal structures and mechanisms. We will cover different techniques used by malware authors to hide the presence of their malware from users and antivirus products.

We will look at different advanced kernel-mode hooking techniques, process injection in kernel mode, and how to perform static and dynamic analysis there.

Before we get into rootkits and learn how they are implemented, we need to understand how the operating system (OS) works and how rootkits can target different parts of the OS and use it to their advantage.

In this chapter, we will cover the following topics:

  • Kernel mode versus user mode
  • Windows internals
  • Rootkits ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Mastering Malware Analysis

Mastering Malware Analysis

Alexey Kleymenov, Amr Thabet

Publisher Resources

ISBN: 9781803240244Supplemental Content