TGViewer
Security Analysis Security Analysis @securation · 12.4K subscribers
Post #1636 5.63K
⭕️ اگر علاقه مند به توسعه RootKit در محیط ویندوز هستید پروژه ای توسعه داده شده که به مطالعه آن میپردازیم.
از ویژگی های این پروژه میتوان به موارد زیر اشاره کرد:

Kill processes

ZwTerminateProcess is simply called from kernel land to terminate any process. Additionally, you can bury a process to avoid it to restart by setting a kernel callback to process creation: If the target process is created, Banshee will set the CreationStatus of the target process to STATUS_ACCESS_DENIED.

Change protection levels

This is done by modifying the EPROCESS structure, which is an kernel object that describes a processes attributes. It also holds a value that specifies the protection level of the process.
We can directly modify this value (aka Direct Kernel Object Modification or DKOM), since we are operating in Ring 0.

Elevate any process token to SYSTEM

EPROCESS also holds a pointer to the current access token, so we can just make it point to e.g. the token of process 4 (SYSTEM) to elevate any process to SYSTEM

Enumerating and erasing kernel callbacks

For now, only Process- and Thread-Creation kernel callbacks are enumerated, by parsing the PsSetCreateNotifyProcess/ThreadRoutine routine to reach the private Psp* routine and then parsing the address of the array, where kernel callbacks are stored.

Protecting the driver file

By hooking the NTFS filesystem's IRP_MJ_CREATE handler, we can block any process from opening a handle to our driver file

Hide Process by PID

Again, EPROCESS comes to help here - it contains a LIST_ENTRY of a doubly linked list called ActiveProcessLink which is queried by Windows to enumerate running processes. If we simply unlink an entry here, we can hide our process from tools like Process Monitor or Task Manager.

#RedTeam #RootKit #MalDev
@securation
GitHub GitHub - eversinc33/Banshee: Experimental Windows x64 Kernel Rootkit with anti-rootkit evasion features. Experimental Windows x64 Kernel Rootkit with anti-rootkit evasion features. - eversinc33/Banshee
More from @securation
  1. Oct 9, 2026⭕️تحلیل آسیب پذیری تلگرام تلگرام scheme مربوط به tg:// رو در سیستم‌عامل register میکنه؛ کل…
  2. Oct 9, 2026‌ حماقت بزرگی است که آدمی به منظور برنده شدن در بیرون، در درون ببازد، یعنی برای شوکت، مقام…
  3. Oct 8, 2026میدونستید اگر باگ بانتی ایرانی کار کنید هر مبلغی که دریافت می‌کنید باید یکسال یا دوسال یا…
  4. Oct 5, 2026⭕️ خطرات امنیتی پنهان در فناوری Direct-to-Cell (D2C) فناوری Direct-to-Cell این امکان را فر…
  5. Oct 5, 2026⭕️ارتباطات ماهواره‌ای استارلینک و فناوری‌های سلولی منابع ارائه شده به بررسی جامع فناوری ار…
  6. Sep 28, 2026ترس توی ذهن آدم با فکر کردن بزرگتر میشه. اما وقتی دست به اقدام میزنی کوچیکتر میشه. @secura…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →