white-papers-defeating-anti-forensics-in-contemporary-complex-threats.pdf
ID: e426dcd5-8670-4e52-807f-1a20f0517de2
STIX ID: report--e426dcd5-8670-4e52-807f-1a20f0517de2
Threat Score
75/100
Uploaded: 2026-08-05
Published Date: 2026-08-05
Last Modified Date: 2026-08-05
Created by: gogogo
TLP:GREEN
...
...
This paper analyzes contemporary anti-forensic techniques used by complex threats — specifically hidden encrypted storage implemented by bootkits and rootkits (e.g., TDL4/Olmarik, Olmasco, Rovnix/Carberp, ZeroAccess, Hodprot). It describes architecture and on-disk layouts of hidden file systems, kernel-mode protection hooks and encryption schemes, and presents a forensic countermeasure (a Hidden FS Reader tool) to recover concealed payloads and configuration data.
