white-papers-defeating-x-64-modern-trends-of-kernel-mode-rootkits.pdf
ID: e762e544-b314-40b4-9dfd-99dce5a8c6a7
STIX ID: report--e762e544-b314-40b4-9dfd-99dce5a8c6a7
Threat Score
78/100
Uploaded: 2026-08-05
Published Date: 2026-08-05
Last Modified Date: 2026-08-05
Created by: gogogo
TLP:GREEN
...
...
This ESET technical presentation analyzes the evolution and modern techniques of x64 kernel-mode rootkits and bootkits (TDL4/Olmarik and Win64/Rovnix). It details installation flows, methods to subvert Windows kernel-mode code signing and PatchGuard (BCD manipulation, WinPE abuse, bootloader/MBR/VBR infection), hidden on-disk file systems, driver loading tricks, and debugging/forensic techniques (Bochs, WinDbg, HiddenFsReader). The paper includes code snippets, diagrams, and indicators (file names and MD5s) useful for detection and analysis.
