Reversing a Windows Kernel Driver Rootkit

Reported 03 Aug 2026 by otx · Severity: medium

A sophisticated Windows kernel-mode rootkit initially misidentified as Cobalt Strike Beacon operates from Ring 0 to compromise system security. The driver patches Event Tracing for Windows (ETW), employs Direct Kernel Object Manipulation (DKOM) to hide processes, hooks the NSI dr