Repository navigation
Releases: slep2-0/WindowsRootkit
Release list
v2.1.1
Enhancements:
COMPLETE Virtual memory protection, only ZwFreeVirtualMemory is now allowed to be called without a hook placed on it, as to use the memory after you must call NtAlloc (or ZwAlloc -> NtAlloc) and that's hooked so.
NOTE: Functions inside of the executable (win32api, ntapi, syscalls, everything), will NOT be able to be used on the process, even on itself, as they are hooked to prevent so, if the hook is activated on that PID. (VirtualAlloc,VirtualProtect,VirtualQuery)
Full Changelog: memory-hook-change...memory-hook-enchancement -- Use latest commits.
v2.1
Changes:
Instead of blocking address via MmIsAddressValid, we also block MmCopyVirtualMemory and ZwQueryVirtualMemory for the pid - essentially restricting VIRTUAL memory access for the PID, physical memory would come at the next update, ensuring complete memory isolation.
Full Changelog: hooking...memory-hook-change -- Use latest commits instead.
v2.0
New Features:
Function Hooking introduced.
Hooking abilities for now:
Block an address from MmIsAddressValid - Will always return false (block ranges).
Block a PID from being accessed in PsLookupProcessByProcessId - Kernel and drivers that use this function WONT be able to interact with the process bearing the PID. -- This includes this rootkit. (Process Hiding and Process Elevation, Process Protection (Bugcheck version only) , and HideDLL will NOT work on the PID the hook is placed on)
Please give me more ideas for hooking! Soon I will bring the actual good part of the hooking, hooking the registry, hiding files, hooking connections (TCP/UDP), and more.
v1.9
New Feature: DLL Injection via a remote thread.
(Planned to also include SRDI so no LoadLibrary is used, and so will also bypass PPL - i think)
v1.8
Added a new feature: File Protection
File protection means when you activate it on a file, it cannot be deleted, cannot be read, it's basically "locked", nothing can be changed about it.
The next feature would be hiding files using the IRP_MJ_DIRECTORY_CONTROL to filter for directory enumeration.
v1.7 Major
MAJOR UPDATE:
Quality Of Life Updates (ONLY AVAILABLE TO SERVICE DRIVERS):
Added the option for the kernel driver to message back the client about operations done (f.e - If chosen to hide a process, driver will notify if successful or not)
Protection Updates:
Revised protection menu, and added the option to add multiple protections to multiple pids (ACCESS_DENIED protection), as well as to disable.
Full Changelog: protection...major
Next Update:
APC Shellcode Injection.
v1.6
Added a new feature:
Process Protection VIA Callbacks, explanation:
Protecting a process this way will cause an access denied on termination, and also will protect from viewing the memory of the process or writing to it.
v1.5
v1.4
v1.3
Support for Windows 7 and XP has been added.
Garbage code removed.
Bug fixes.
Support for service creation has been added, please use the RootkitDriverService.sys if you wish to use a service, or use the RootkitDriverReflective.sys if you wish to use a reflective mapping method, like KDMapper. (I suggest the first one, way easier and less detectable, also permanent).
Service Creation (Permanent, at system start, not boot):
sc create SERVICENAME type= kernel binPath= "C:\Path\To\RootkitDriverService.sys" start= system
Update - I can't really call this less detectable because the driver is unsigned and you must use testsigning in order to load it in the computer, either that or bring your own vulnerable driver attack, which KDMapper uses (so you'll need the reflective version) (DSE Operates this, you may find solutions to disable DSE, or bypass it entirely, I will not introduce those solutions here.)