22.03.2013 Views

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

The Rootkit Primer - Below Gotham Labs

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Kernel Objects<br />

Object → Abstraction of a System Resource<br />

Operations are performed by the Object Manager subsystem<br />

Objects are implemented as C structures (blobs of related data)<br />

Examples: nt!_EPROCESS, nt!_DRIVER_OBJECT, nt!_TOKEN<br />

Can examine via a kernel debugger (cue the Star Wars music…)<br />

© <strong>Below</strong> <strong>Gotham</strong> <strong>Labs</strong>, 2009<br />

16

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!