Rootkit development

Hello everyone! I hope all of you are doing well.

I'm looking for any advice on how to start to build a PoC Rootkit that first infects an OS and stays "alive" inside a Linux Live USB OS. Nothing special, just creating a file there or something else.

I've found some articles about exploiting the ACPI tables to do it, but didn't find a deeper approach on how to build the rootkit. The same goes for UEFI rootkits, PCI, etc.

I'm looking for anything that can help me to build my own, it's just a Proof of concept, so it doesn't need to evade things like Secure Boot or other security measures.

Any help is appreciated!

EDIT: added ACPI article link

submitted by /u/Lucisu
[link] [comments]

from hacking: security in practice https://ift.tt/3GtPiez

Comments