To achieve maximum stealth and obtain unabated access to the system, rootkits execute in kernel mode. This course focuses on the kernel interfaces (APIs), data structures and mechanisms that are exploited by rootkits to achieve their goals at every stage of their execution. Kernel security enhancements that have been progressively added from Windows 7 to the latest version of Windows are discussed along with some circumvention techniques. Every topic in this course is accompanied by hands-on labs where attendees get to implement key components of a rootkit and test them on 64-bit Windows systems to reinforce their understanding of the theory. By learning how rootkits actually work, attendees are able to detect and defend against them.
Understand vulnerabilities in the Windows kernel and device drivers
Be able to write and modify kernel mode exploits
Understand the security enhancements that have been added to recent versions of Windows
Be able to bypass some of the security mitigations in recent versions of Windows
Understand the post-exploitation steps performed by kernel mode rootkits
Understand the techniques used by popular real world rootkits
Understand how rootkits hide their presence in the system
Understand how rootkits communicate with command and control (C&C) servers
Be able to identify malicious behavior and defend against rootkits
The materials within this course focus on the Knowledge Skills and Abilities (KSAs) identified within the Specialty Areas listed below. Click to view Specialty Area details within the interactive National Cybersecurity Workforce Framework.