Posts

Showing posts with the label #SakDriver

SakDriver: Kernel Driver Rootkit Research Notes - Technical Analysis and Design Insights into Registry Callback-Based Stealth Communication in Kernel-Mode Rootkits

Image
  SakDriver: Kernel Driver Rootkit Research Notes Technical Analysis and Design Insights into Registry Callback-Based Stealth Communication in Kernel-Mode Rootkits     “To understand the immeasurable, the mind must be extraordinarily quiet, still.” — Jiddu Krishnamurti     Seeker( 李标明 ) · @clibm079    China · Independent Malware Analyst & Researcher  From 2026.08.21 to 2026.08.27 Prologue: Curiosity-driven, keep moving and transcending the past I came across a new rootkit malware called SakDriver during that quiet exploration stage, which gained extremely high attention when it was shared on the X platform. After finishing the last article about “Windows Internals: Research Notes from the 6th to 7th Edition” on Aug 10, 2026, I started to analyze this kernel driver. It’s very cool and a valuable malware to research.   It took me about one week to read the ...