Skip to content
x64 usermode rootkit
C++
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
latebros
littlebro fixed UB in generate_shellcode Nov 24, 2017
.gitattributes
.gitignore
LICENSE
README.md
latebros.sln

README.md

latebros

x64 usermode rootkit. This was a project i made (with help from Daax and JustMagic) while researching usermode rootkits. Project is neither under development nor finished.

Capabilities

  • Hide process from enumeration
  • Hide registry key from enumeration
  • Hide file for modification
  • Protect process from modification
  • Protect file from modification
  • Protect registry key from erasure

Hooks

  • ntdll.dll!NtOpenProcess
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtQueryDirectoryFile
  • ntdll.dll!NtDeleteValueKey
  • ntdll.dll!NtEnumerateValueKey

Thanks to

  • Daax
  • JustMagic
You can’t perform that action at this time.