Skip to content

Releases: slep2-0/WindowsRootkit

v2.1.1

Choose a tag to compare

@slep2-0 slep2-0 released this 13 Jul 22:47
6ebda36

Enhancements:

COMPLETE Virtual memory protection, only ZwFreeVirtualMemory is now allowed to be called without a hook placed on it, as to use the memory after you must call NtAlloc (or ZwAlloc -> NtAlloc) and that's hooked so.

NOTE: Functions inside of the executable (win32api, ntapi, syscalls, everything), will NOT be able to be used on the process, even on itself, as they are hooked to prevent so, if the hook is activated on that PID. (VirtualAlloc,VirtualProtect,VirtualQuery)

Full Changelog: memory-hook-change...memory-hook-enchancement -- Use latest commits.

v2.1

Choose a tag to compare

@slep2-0 slep2-0 released this 13 Jul 19:40
32e41c9

Changes:

Instead of blocking address via MmIsAddressValid, we also block MmCopyVirtualMemory and ZwQueryVirtualMemory for the pid - essentially restricting VIRTUAL memory access for the PID, physical memory would come at the next update, ensuring complete memory isolation.

Full Changelog: hooking...memory-hook-change -- Use latest commits instead.

v2.0

Choose a tag to compare

@slep2-0 slep2-0 released this 12 Jul 20:03
d2c4d3c

New Features:

Function Hooking introduced.

Hooking abilities for now:
Block an address from MmIsAddressValid - Will always return false (block ranges).
Block a PID from being accessed in PsLookupProcessByProcessId - Kernel and drivers that use this function WONT be able to interact with the process bearing the PID. -- This includes this rootkit. (Process Hiding and Process Elevation, Process Protection (Bugcheck version only) , and HideDLL will NOT work on the PID the hook is placed on)

Please give me more ideas for hooking! Soon I will bring the actual good part of the hooking, hooking the registry, hiding files, hooking connections (TCP/UDP), and more.

v1.9

Choose a tag to compare

@slep2-0 slep2-0 released this 10 Jul 14:26
825b3f2

New Feature: DLL Injection via a remote thread.

(Planned to also include SRDI so no LoadLibrary is used, and so will also bypass PPL - i think)

v1.8

Choose a tag to compare

@slep2-0 slep2-0 released this 11 May 15:08
cdb4356

Added a new feature: File Protection

File protection means when you activate it on a file, it cannot be deleted, cannot be read, it's basically "locked", nothing can be changed about it.

The next feature would be hiding files using the IRP_MJ_DIRECTORY_CONTROL to filter for directory enumeration.

v1.7 Major

Choose a tag to compare

@slep2-0 slep2-0 released this 08 May 23:02
493e17d

MAJOR UPDATE:

Quality Of Life Updates (ONLY AVAILABLE TO SERVICE DRIVERS):

Added the option for the kernel driver to message back the client about operations done (f.e - If chosen to hide a process, driver will notify if successful or not)

Protection Updates:
Revised protection menu, and added the option to add multiple protections to multiple pids (ACCESS_DENIED protection), as well as to disable.

Full Changelog: protection...major

Next Update:

APC Shellcode Injection.

v1.6

Choose a tag to compare

@slep2-0 slep2-0 released this 07 May 11:37
ab90175

Added a new feature:

Process Protection VIA Callbacks, explanation:

Protecting a process this way will cause an access denied on termination, and also will protect from viewing the memory of the process or writing to it.

v1.5

Choose a tag to compare

@slep2-0 slep2-0 released this 06 May 17:58
2340ca4

Added the feature to unprotect a protected process.

v1.4

Choose a tag to compare

@slep2-0 slep2-0 released this 06 May 10:20
2ea5d48

New Update -
Added the feature to hide DLL's.
Added the feature to unload the Driver only if loaded via a service.

v1.3

Choose a tag to compare

@slep2-0 slep2-0 released this 04 May 08:43
e1b713a

Support for Windows 7 and XP has been added.
Garbage code removed.
Bug fixes.

Support for service creation has been added, please use the RootkitDriverService.sys if you wish to use a service, or use the RootkitDriverReflective.sys if you wish to use a reflective mapping method, like KDMapper. (I suggest the first one, way easier and less detectable, also permanent).

Service Creation (Permanent, at system start, not boot):

sc create SERVICENAME type= kernel binPath= "C:\Path\To\RootkitDriverService.sys" start= system

Update - I can't really call this less detectable because the driver is unsigned and you must use testsigning in order to load it in the computer, either that or bring your own vulnerable driver attack, which KDMapper uses (so you'll need the reflective version) (DSE Operates this, you may find solutions to disable DSE, or bypass it entirely, I will not introduce those solutions here.)