搜索资源列表
AFXRootkit2005
- 一个用delphi开发的开源rootkit代码,可以隐藏文件,目录,进程,句柄等信息。-used to develop an open-source code rootkit can hide files, directories, processes, handle such information.
FU_Rootkit.zip
- rootkit工具,可以隐藏进程和驱动,rootkit tool to hide processes and drive
source
- 一个很好的反rootkit例子,终止其运用或替换 重要system dlls.-A good example of anti-rootkit, to terminate the use or replacement of important system dlls.
CsrssWalker
- 在Csrss.exe中,保存着所有Win32子系统进程的进程信息,这些信息以链表的形式保存。 正常情况下,每一个新创建的进程都会通知Csrss.exe,Csrss.exe接收这些信息然后保存起来,所以遍历这个链表就可以得到所有Win32子系统进程的信息。首先就是找链表头了,链表头为CsrssRootProcess,在CSRSRV.DLL导出的函数中有对CsrssRootProcess的操作,因此可以通过CSRSRV.DLL的导出函数找到CsrssRootProcess。 通过遍历这个链表
source
- source code for hiding via rootkit style
enyelkm.en.v1.1.tar
- ENYELKM rootkit, source code. www.ossec.net/rootkits/enye-sec.php
Rootkitahook
- 很经典的系统内核的编程资料。内含经典ROOTKIT源代码。主要介绍了如何利用HOOK来操作内核。-The classic system kernel programming information. Contains classic ROOTKIT source code. Is mainly introduced how HOOK kernel to operate.
BIOS_ROOTKIT
- BIOS ROOTKIT 学习资料及源码-The BIOS ROOTKIT learning information and source
CodeGate2011.bootkit
- MBR Rootkit Source with Assembly-MBR Rootkit Source
ScDetective-master
- ScDetective - Full Source A kernel level Anti-Rootkit tool which runs on the windows platform. ## Basic information - GUI : VS2008 - MFC - Driver :VS2005 - ddkwizard - DDK Version:7600.16385.1 - Debug : Windbg - VirtualKD - VMware -
agony-rootkit
- this the agony rootkit source code.-this is the agony rootkit source code.
HideProcessHookMDL-master
- Simple rootkit source code
the_flying_circus
- One of the best rootkit source code for MacOS supporing 10.x platform.
