Rookits

Rookit overview:

API
Allocated memory

VirtualAlloc

0x72120010

OpenProcess

0x72122200

ListProcesses

0x721211000 malicious process overwrites and injects own i.e 0x6660000 which directs back to evil.dll

Hook

Identifying rootkits with Volatility:

Vol2 module
Vol3 module
Description of use

apihooks

N/a

find userland IAT, inline and trampoline hooks

idt

N/a

display interrupt descriptor table entries

ssdt

windows.ssdt

display system service descriptor table entries

driverirp

windows.driverirp

identify I/O Request Packets (IRP) hooks

pscview

N/a

Find hidden processes via cross-view techniques

modules

windows.modules

View list of loaded kernel drivers

modscan

windows.modscan

Find drivers via pool tag scanning

Last updated