本文へ移動
cccskills
無料GitHub で公開

dissecting-boot-and-kernel-rootkits

Analyzes bootkit and rootkit samples by identifying boot-process tampering (MBR/VBR/ UEFI), kernel-mode components, and stealth hooking techniques from static indicators. Activates for requests to analyze a bootkit or rootkit, examine MBR/UEFI tampering, or identify kernel-mode stealth components.

インストール方法を見る

含まれるファイル(4)

  • SKILL.md2.8 KB
  • LICENSE340 B
  • references/api-reference.md1.3 KB
  • scripts/analyst.py3.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Dissecting Boot and Kernel Rootkits

When to Use

  • You have a sample (MBR/VBR image, UEFI module, or kernel driver) suspected of boot-process or kernel-level tampering and stealth.
  • You need to identify the persistence vector and stealth technique class statically.

Do not use this on production firmware/boot media without acquisition — analyze a captured image. The skill reads bytes statically and executes nothing.

Prerequisites

  • The boot image / UEFI module / driver (read inertly).

Safety & Handling

  • Read bytes statically; never write the sample to boot media or load the driver.

Workflow

Step 1: Classify the artifact

python scripts/analyst.py classify sample.bin

Detects MBR/VBR (boot signature 0x55AA at 0x1FE), UEFI modules (PE with EFI subsystem / PI GUIDs / EFI_ strings), and kernel drivers (PE importing ntoskrnl/hal, .sys indicators).

Step 2: Identify tampering / hooking indicators

Flag disk-write primitives (Int 13h for MBR bootkits), SSDT/IRP hooking and Zw*/Ke* kernel APIs, DKOM strings, and driver-callback registration.

Step 3: Map the persistence vector

Determine whether persistence is via MBR/VBR overwrite, UEFI variable/module, or driver service.

Step 4: Document

Record the artifact type, persistence vector, and stealth technique class, mapping to ATT&CK.

Validation

  • The artifact type is identified by concrete signatures (boot signature, PE subsystem, imports).
  • Tampering/hooking indicators reference real primitives, not generic strings.
  • The persistence vector is stated with its evidence.

Pitfalls

  • A legitimate bootloader/driver resembling a bootkit/rootkit — corroborate with behavior.
  • UEFI modules requiring firmware-volume parsing beyond simple PE checks.
  • Kernel samples needing signed-driver and callback context to confirm stealth.

References

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Reverses Android malware: unpacking APKs, decompiling DEX bytecode to readable Java, auditing the manifest for abused permissions and components, and locating dynamically loaded or native payloads. Activates for requests to analyze an APK, decompile DEX, or investigate a suspicious Android app.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes API call traces from a sandbox or API monitor (JSON) to group calls by category, reconstruct high-level behaviors (process injection, file drops, network, crypto), and flag suspicious call sequences. Activates for requests to analyze an API trace, interpret sandbox API logs, or identify behavior from Win32/Native API calls.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Windows Authenticode signatures on PE files: checking for a signature, reading the signer certificate chain, detecting revoked/expired/stolen certs, and recognizing signature-stripping and catalog-signing abuse. Activates for requests to analyze a code signature, verify Authenticode, or assess signer trust on a PE.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes banking trojan webinject configurations to extract targeted institutions, injected JavaScript/HTML, and data-theft hooks, mapping the fraud workflow. Activates for requests to analyze banking trojan webinjects, parse a webinject config, or map targeted banks and credential-theft injections.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes Python-based malware packaged as PyInstaller/py2exe executables by detecting the packer, locating the embedded archive, and identifying bundled .pyc modules for extraction and decompilation. Activates for requests to analyze compiled Python malware, unpack a PyInstaller binary, or extract pyc modules from a frozen Python executable.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

Analyzes cryptojacking/coinminer malware by extracting mining pool endpoints (stratum), wallet addresses, algorithm and miner identifiers (XMRig and forks), and persistence or resource-control settings from static strings and config. Activates for requests to analyze a cryptominer, extract mining pool and wallet IOCs, or identify coinminer configuration.

日本語の概要は準備中です。原文の説明を表示しています。

meltedinhex/analyst-ai-pack212026年7月7日 更新

meltedinhex のスキルをすべて見る

このスキルの問題を報告する