Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
BSD 2-Clause "Simplified" License
1.61k
stars
392
forks
source link
r77 rookit injects into PROCESS_CREATION_MITIGATION_POLICY_BLOCK_NON_MICROSOFT_BINARIES_ALWAYS_ON process #67
Closed
wineggdrop closed 8 months ago