Hi.
Maybe, it would be interesting for someone.
Slides from my ZeroNights 2012 talk about the rootkits and vulns: http://dl.dropbox.com/u/22903093/Applie ... ensics.pdf
Source code of the rootkit from the presentation: https://github.com/Cr4sh/WindowsRegistryRootkit (described inside)
Maybe, it would be interesting for someone.
Slides from my ZeroNights 2012 talk about the rootkits and vulns: http://dl.dropbox.com/u/22903093/Applie ... ensics.pdf
Source code of the rootkit from the presentation: https://github.com/Cr4sh/WindowsRegistryRootkit (described inside)