|
|
|
Date Submitted:
01/20/06
Hits: 68 Rating: ![]() ![]() ![]() ![]() based on 0 votes
Thoughts about Cross-View based Rootkit DetectionAdded by Papergrl
Description:
Cross-view based detectors, like Rootkit Revealer, compare a "low level" system view with a "high level" view. Let's focus here on hidden files detection on Windows systems. How to obtain a low level view of the file system? Of course by reading a raw disk sectors and parsing them according to NTFS layout.
Read the Complete Paper You don't have permission to post replies. Please login or register. |
