Poised Solutions Library

Poised Solutions Tech Library

book review
the rootkit arsenal

Poised Solutions

The Rootkit Arsenal Book Review

IT Security

IT Library

The Rootkit Arsenal

The Rootkit Arsenal

Amazon UKAmazon USA
The Rootkit Arsenal
Author:
Reverend Bill Blunden
Publisher:
Wordware
Published:
2009
Pages:
908

The Rootkit Arsenal


The Rootkit Arsenal Chapters

The Rootkit Arsenal Chapters
  1. Setting the Stage
    • Forensic Evidence
    • First Principles
    • The Malware Connection
    • Closing Thoughts
  2. Into the Catacombs: IA-32
    • IA-32 Memory Models
    • Real Mode
    • Protected Mode
    • Implementing Memory Protection
  3. Windows System Architecture
    • Physical Memory
    • Memory Protection
    • Virtual Memory
    • User Mode and Kernel Mode
    • The Native API
    • The Boot Process
    • Design Decisions
  4. Rootkit Basics
    • Rootkit Tools
    • Debuggers
    • A Rootkit Skeleton
    • Loading a KMD
    • Installing and LAunching a Rootkit
    • Self-Healing Rootkits
    • Windows Kernel Mode Security
    • Synchronization
    • Commentary
  5. Hooking Call Tables
    • Hooking in User Space: The IAT
    • Hooking in Kernel Space
    • Hooking Countermeasures
    • Counter Countermeasures
  6. Patching System Routines
    • Run-time Patching
    • Binary Patching
    • Instruction Patching Countermeasures
  7. Altering Kernel Objects
    • The Cost of Invisibility
    • Revisiting the EPROCESS Object
    • The DRIVER_SECTION Object
    • The TOKEN Object
    • Hiding a Process
    • Hiding a Driver
    • Manipulating the Access Token
    • Using No-FU
    • Countermeasures
    • Commentary: Limits of the Two-Ring Model
    • The Last Lines of Defense
  8. Deploying Filter Drivers
    • Filter Driver Theory
    • An Example: Logging Keystrokes
    • Adding Functionality: Dealing with IRQLs
    • Key Logging: Alternative Techniques
    • Other Ways to Use Filter Drivers
  9. Defeating Live Response
    • IDS, IPS and Forensics
    • The Live Incident Response Process
    • RAM Acquisition
  10. Defeating File System Analysis
    • File System Analysis
    • Countermeasures: Overview
    • Countermeasures: Forensic Duplication
    • Countermeasures: Deleted File Recovery
    • Countermeasures: Acquiring Metada
    • Countermeasures: Removing Known Files
    • Countermeasures: File Signature analysis
    • Countermeasures: Executable Analysis
    • Borrowing Other Malware Tactics
  11. Defeating Network Analysis
    • Worst-Case Scenario: Full Content Data Capture
    • Tunneling: An Overview
    • The Windows tcp/IP Stack
    • DNS Tunneling
    • DNS Tunneling: User Mode
    • DNS Tunneling: WSK Implementation
    • NDIS Protocol Drivers
  12. Countermeasure Summary
    • Live Incident Response
    • File System Analysis
    • Network Traffic Analysis
    • Why Anti-Forensics?
  13. The Tao of Rootkits
    • Run Silent, Run Deep
    • Development Mindset
    • On Dealing with Proprietary Systems
    • Saking Out the Kernel
    • Walk before You Run: Patching System Code
    • Walk before You Run: Altering System Data Structures
    • The Advantages of Self-Reliant Code
    • Leverage Existing Work
    • Use a Layered Defense
    • Study Your Target
    • Separate Mechanism from Policy
  14. Closing Thoughts
The Rootkit Arsenal Appendices
  1. Chapter 2
  2. Chapter 3
  3. Chapter 4
  4. Chapter 5
  5. Chapter 6
  6. Chapter 7
  7. Chapter 8
  8. Chapter 10
  9. Chapter 11

Penetration







































Poised Solutions Web Development and Web Design by Poised Solutions IT Practice

Guild of Developers  •  PantheonOS  •  Cyber Security