Rust Based Windows Kernel Rootkit
by Loki - Saturday August 3, 2024 at 05:43 PM
#21
this is very usefull

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: advertising his telegram in database section without MVP rank
Reply
#22
thank you for sharing, do you also unhook .dll when using ZwCreateThreadEx?
Reply
#23
Is it a code or a tool?
Reply
#24
(Aug 03, 2024, 05:43 PM)Loki Wrote: Features
Process
  • Process (Hide / Unhide) ✅
  • Process Signature (PP / PPL) ✅
  • Process Protection (Anti-Kill / Dumping) ✅
  • Elevate Process to System ✅
  • Terminate Process ✅
  • Lists protected and hidden processes currently on the system ✅
Thread
  • Thread (Hide / Unhide) ✅
  • Thread Protection (Anti-Kill) ✅
  • Lists protected and hidden threads currently on the system ✅
Driver
  • Driver (Hide / Unhide) ✅
  • Enumerate Driver ✅
  • Driver Signature Enforcement (DSE)
  • DSE (Enable / Disable) ✅
  • Keylogger
  • Keylogger (Start / Stop) ✅
Callbacks
  • List / Remove / Restore Callbacks
  • PsSetCreateProcessNotifyRoutine ✅
  • PsSetCreateThreadNotifyRoutine ✅
  • PsSetLoadImageNotifyRoutine ✅
  • Module
  • Enumerate Module ✅
Registry
  • Registry Protection (Anti-Deletion e Overwriting) ✅
  • Injection Shellcode
  • Process Injection (ZwCreateThreadEx) ✅
  • APC Injection ✅



Omnicer
you're the goat, always new stuff to learn thank you
Reply
#25
Thanks for sharing
Reply
#26
Lets see pleaseeeeeeee
Reply
#27
rust is the goat when it comes to malware
Reply
#28
good work thanks
Reply
#29
Rust is king when it comes to malware....

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Leeching | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#30
(Aug 03, 2024, 05:43 PM)Loki Wrote: Features
Process
  • Process (Hide / Unhide) ✅
  • Process Signature (PP / PPL) ✅
  • Process Protection (Anti-Kill / Dumping) ✅
  • Elevate Process to System ✅
  • Terminate Process ✅
  • Lists protected and hidden processes currently on the system ✅
Thread
  • Thread (Hide / Unhide) ✅
  • Thread Protection (Anti-Kill) ✅
  • Lists protected and hidden threads currently on the system ✅
Driver
  • Driver (Hide / Unhide) ✅
  • Enumerate Driver ✅
  • Driver Signature Enforcement (DSE)
  • DSE (Enable / Disable) ✅
  • Keylogger
  • Keylogger (Start / Stop) ✅
Callbacks
  • List / Remove / Restore Callbacks
  • PsSetCreateProcessNotifyRoutine ✅
  • PsSetCreateThreadNotifyRoutine ✅
  • PsSetLoadImageNotifyRoutine ✅
  • Module
  • Enumerate Module ✅
Registry
  • Registry Protection (Anti-Deletion e Overwriting) ✅
  • Injection Shellcode
  • Process Injection (ZwCreateThreadEx) ✅
  • APC Injection ✅



Omnicer
thx for the post
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Python Chrome Data Stealer (url, username/email, password, etc) Discord Webhook mooning 140 9,304 Yesterday, 05:37 PM
Last Post: gergergergerg5825g651eg
  Xordium stealer for Pulsar v2.4.5 nullvex 23 818 Yesterday, 02:48 PM
Last Post: kochamapi4api
  Bypass AV and EDR - Halos Gate from Sektor7 0x01 124 11,022 Apr 25, 2026, 11:13 AM
Last Post: Ususuussss
  Malware On Steroids Carpenter12 0 77 Feb 10, 2026, 07:06 PM
Last Post: Carpenter12
  Malware Extension Spoofer Psych1c 19 611 Feb 10, 2026, 08:02 AM
Last Post: ucy

Forum Jump:


 Users browsing this forum: 1 Guest(s)