
Theory: Foreword, What is a rootkit?, Rootkit structure, Examples of rootkits, What you need to know to start, Compatibility and current code version, Further reading
Set up tools for development and reverse engineering, including Visual Studio 2010, a debugger, preview, and hex editor; build a hello world console project to inspect headers, imports, and sections.
Theory: Assembly language crash course, Register types, Instruction syntax, Writing shellcode, Shellcode writing: the essentials, Glossary, Code injection, Notes about the 64-bit architecture
Explore shellcode development and inside-process termination by injecting code, allocating memory, writing to process memory, and starting a remote thread using debugging tools.
Theory: Intro, Writing rootkit code, Hiding processes, Hiding files and registry entries, Notes on 64-bit architecture
Examine how processes are hidden by altering the system information query and injecting a dll to alter the process list, and discuss defensive methods to detect and reveal hidden processes.
Theory: Hiding files
Discover how stealth apps hide files and directories by intercepting directory enumeration calls and modifying return data through function hooking and import-table tricks.
Theory: Intro, Notes about the 64-bit mode, Hiding registry entries
Demonstrates how attackers hide a registry entry by hooking the Regnum value function and injecting a library to mask value 3 in a registry key.
Theory: Creating a backdoor to a system, Keylogger, Taking a screenshot, Sending logs, Autorun
Create a keylogger that records keystrokes, saves logs to a file or sends them to a remote server, captures screenshots, and transmits data using system hooks and background threads.
Theory: Remote console
Theory: What defense mechanisms are included in Windows?
Learn core Windows security features—SLR (address space layout randomisation), DEP, Patch Guard, digital driver signatures, UAC, and the built-in firewall—and how they deter exploits and enforce safe, signed code.
Theory: Understanding how antiviruses detect threats, Signatures
Learn how antivirus software detects threats using signatures and emulation, then analyze and modify a program to evade detection and pass virus total checks.
Theory: Heuristics, Deceiving a heuristic scanner
Learn how heuristic scanners detect suspicious activity and how encoding techniques and entropy affect detection. The module demonstrates base64 encoding, function name obfuscation, and emulation to reveal antivirus responses.
Theory: Emulation, RC4 overview, System calls and 64-bit architecture
Explore anti-emulation techniques that counter antivirus emulation and reveal how malware evades detection through emulation and analytics tools like VirusTotal.
Theory: Bypassing a firewall, Modifying the remote console
Explore how an attacker bypasses a firewall using browser-based code injection, manipulating port rules and stealthy processes to exfiltrate logs and screenshots via http uploads with base64 and multipart data.
Theory: Areas for hiding programs, Running a program as a system service, Dll spoofing
Learn how attackers keep a rootkit alive by auto starting in registry, start menu or services, plus dl spoofing and code injection, with practical demonstrations.
Theory: Rootkit detectors
Detect IHG hooking and import-table hooks to counter threats, using GMUR to identify modifications. Track network activity with Wireshark and net tool to reveal the key logger's unauthorized data transmission.
LAST UPDATED: 11/2024
Rootkits and Stealth Apps: Creating & Revealing 2.0 HACKING
Ethical Hacking in Practice. Complete guide to rootkit and stealth software development. Practical ROOTKIT HACKING 101
Before we begin: the practical use of the course you are going to see has been proven by thousands of people all over the world – beginners and computer geeks as well. People who make their first steps in computer / network security and professionals: network administrators, programmers, pentesters, black- and white hat hackers. Please, read carefully what we'd like to share with you.
A rootkit is a stealthy type of software, typically malicious, designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer. - definition by Wikipedia
You can ignore the fact that rootkits really exist,
You can pretend that goverment agencies don't use rootkits,
You can even believe that big companies don't spend huge amount of money for developing malicious software that can spy on you and your family,
You can just turn a blind eye on it and ignore these fact.
But it does not make the problem disappear.
Therefore we decided to face facts and show you how rootkits work, how they can hide inside your system, how to create such an invisible software, how to detect and protect against those threats.
This course covers all the important techniques related with ROOTKITS AND CREATING INVISIBLE SOFTWARE used by hackers, system administrators, pentesters and IT forensic analysts.
What you can expect from this course:
You'll learn how to create shellcode
You'll learn how to inject code into processes
You'll learn how to hide processes, files, directories and registry entries
You'll learn how to keep a rootkit in a system
You'll learn how to create a backdoor
You'll learn how to create an invisible keylogger and remote console
You'll learn how to make a screenshot
You'll learn how to create undetectable applications
You'll learn how to deceive Anti-Virus applications
You'll learn how to use anti-emulation techniques
You'll learn how to bypass a firewall
You'll learn how to create a rootkit detector
You'll learn how to protect against rootkits
And many other interesting topics
We guarantee your 100% satisfaction or you will get your money back. You have 30 days to decide if this course is for you. You will get access to the whole system. If for any reason you're not satisfied with your training, you will get a full refund. No questions asked.
Good luck and see you on the other side,
Andrew Harper || ITsec Academy || Hacking School Team