I am looking for rootkits that will work on Windows 8 , try to put together a pool of those . I tried testing some but they didnt seem to work, so i thought i would ask here if anyone has gone down that road before ?
A forum for reverse engineering, OS internals and malware analysis
dphrag wrote:didn't know that Necurs works on Win8 ! When i even tried some ark's tools they failed to work also. Guess have to wait .Have no idea will it work or no. But more likely will. Well better chance than any other because Necurs is not rootkit. Also forget about ARK software as class. Its useless piece of junk code.
markusg wrote:perhaps from interestYes, that project builds a Windows 8 EFI Bootkit POC able to disable Driver Signing Enforcement and Patchguard... Hope that can help security analyst and, perhaps, normal people, to understand how UEFI technology operates...
http://www.itsec.it/2012/09/18/uefi-tec ... 8-bootkit/