Rootkits: Subverting the Windows Kernel: Subverting the Windows Kernel by Greg Hoglund,Jamie Butler
"It's imperative that everybody working in the field of cyber-security read this book to understand the growing threat of rootkits."
--Mark Russinovich, editor, Windows IT Pro / Windows & .NET Magazine
"This material is not only up-to-date, it defines up-to-date. It is truly cutting-edge. As the only book on the subject, Rootkits will be of interest to any Windows security researcher or security programmer. It's detailed, well researched and the technical information is excellent. The level of technical detail, research, and time invested in developing relevant examples is impressive. In one word: Outstanding."
--Tony Bautts, Security Consultant; CEO, Xtivix, Inc.
"This book is an essential read for anyone responsible for Windows security. Security professionals, Windows system administrators, and programmers in general will want to understand the techniques used by rootkit authors. At a time when many IT and security professionals are still worrying about the latest e-mail virus or how to get all of this month's security patches installed, Mr. Hoglund and Mr. Butler open your eyes to some of the most stealthy and significant threats to the Windows operating system. Only by understanding these offensive techniques can you properly defend the networks and systems for which you are responsible."
--Jennifer Kolde, Security Consultant, Author, and Instructor
"What's worse than being owned? Not knowing it. Find out what it means to be owned by reading Hoglund and Butler's first-of-a-kind book on rootkits. At the apex the malicious hacker toolset--which includes decompilers, disassemblers, fault-injection engines, kernel debuggers, payload collections, coverage tools, and flow analysis tools--is the rootkit. Beginning where Exploiting Software left off, this book shows how attackers hide in plain sight.
"Rootkits are extremely powerful and are the next wave of attack technology. Like other types of malicious code, rootkits thrive on stealthiness. They hide away from standard system observers, employing hooks, trampolines, and patches to get their work done. Sophisticated rootkits run in such a way that other programs that usually monitor machine behavior can't easily detect them. A rootkit thus provides insider access only to people who know that it is running and available to accept commands. Kernel rootkits can hide files and running processes to provide a backdoor into the target machine.
"Understanding the ultimate attacker's tool provides an important motivator for those of us trying to defend systems. No authors are better suited to give you a detailed hands-on understanding of rootkits than Hoglund and Butler. Better to own this book than to be owned."
--Gary McGraw, Ph.D., CTO, Cigital, coauthor of Exploiting Software (2004) and Building Secure Software (2002), both from Addison-Wesley
"Greg and Jamie are unquestionably the go-to experts when it comes to subverting the Windows API and creating rootkits. These two masters come together to pierce the veil of mystery surrounding rootkits, bringing this information out of the shadows. Anyone even remotely interested in security for Windows systems, including forensic analysis, should include this book very high on their must-read list."
--Harlan Carvey, author of Windows Forensics and Incident Recovery (Addison-Wesley, 2005)
Rootkits are the ultimate backdoor, giving hackers ongoing and virtually undetectable access to the systems they exploit. Now, two of the world's leading experts have written the first comprehensive guide to rootkits: what they are, how they work, how to build them, and how to detect them. Rootkit.com's Greg Hoglund and James Butler created and teach Black Hat's legendary course in rootkits. In this book, they reveal never-before-told offensive aspects of rootkit technology--learn how attackers can get in and stay in for years, without detection.
Hoglund and Butler show exactly how to subvert the Windows XP and Windows 2000 kernels, teaching concepts that are easily applied to virtually any modern operating system, from Windows Server 2003 to Linux and UNIX. They teach rootkit programming techniques that can be used for a wide range of software, from white hat security tools to operating system drivers and debuggers.
After reading this book, readers will be able to
* Understand the role of rootkits in remote command/control and software eavesdropping
* Build kernel rootkits that can make processes, files, and directories invisible
* Master key rootkit programming techniques, including hooking, runtime patching, and directly manipulating kernel objects
* Work with layered drivers to implement keyboard sniffers and file filters
* Detect rootkits and build host-based intrusion prevention software that resists rootkit attacks
Publication Details
Title:
Author(s):
Illustrator:
Binding:
Published by: Addison-Wesley Professional: , 2005
Edition:
ISBN: 9780321294319 | 0321294319
352 pages.
Book Condition: Good
cover worn
products.product.pickup_availability.unavailable
Product information


New Zealand Delivery
Shipping Options
Shipping options are shown at checkout and will vary depending on the delivery address and weight of the books.
We endeavour to ship the following day after your order is made and to have pick up orders available the same day. We ship Monday-Friday. Any orders made on a Friday afternoon will be sent the following Monday. We are unable to deliver on Saturday and Sunday.
Pick Up is Available in NZ:
Warehouse Pick Up Hours
- Monday - Friday: 9am-5pm
- 35 Nathan Terrace, Shannon NZ
Please make sure we have confirmed your order is ready for pickup and bring your confirmation email with you.
Rates
-
New Zealand Standard Shipping - $6.00
- New Zealand Standard Rural Shipping - $10.00
- Free Nationwide Standard Shipping on all Orders $75+
Please allow up to 5 working days for your order to arrive within New Zealand before contacting us about a late delivery. We use NZ Post and the tracking details will be emailed to you as soon as they become available. There may be some courier delays that are out of our control.
International Delivery
We currently ship to Australia and a range of international locations including: Belgium, Canada, China, Switzerland, Czechia, Germany, Denmark, Spain, Finland, France, United Kingdom, United States, Hong Kong SAR, Thailand, Philippines, Ireland, Israel, Italy, Japan, South Korea, Malaysia, Netherlands, Norway, Poland, Portugal, Sweden & Singapore. If your country is not listed, we may not be able to ship to you, or may only offer a quoting shipping option, please contact us if you are unsure.
International orders normally arrive within 2-4 weeks of shipping. Please note that these orders need to pass through the customs office in your country before it will be released for final delivery, which can occasionally cause additional delays. Once an order leaves our warehouse, carrier shipping delays may occur due to factors outside our control. We, unfortunately, can’t control how quickly an order arrives once it has left our warehouse. Contacting the carrier is the best way to get more insight into your package’s location and estimated delivery date.
- Global Standard 1 Book Rate: $37 + $10 for every extra book up to 20kg
- Australia Standard 1 Book Rate: $14 + $4 for every extra book
Any parcels with a combined weight of over 20kg will not process automatically on the website and you will need to contact us for a quote.
Payment Options
On checkout you can either opt to pay by credit card (Visa, Mastercard or American Express), Google Pay, Apple Pay, Shop Pay & Union Pay. Paypal, Afterpay and Bank Deposit.
Transactions are processed immediately and in most cases your order will be shipped the next working day. We do not deliver weekends sorry.
If you do need to contact us about an order please do so here.
You can also check your order by logging in.
Contact Details
- Trade Name: Book Express Ltd
- Phone Number: (+64) 22 852 6879
- Email: sales@bookexpress.co.nz
- Address: 35 Nathan Terrace, Shannon, 4821, New Zealand.
- GST Number: 103320957 - We are registered for GST in New Zealand
- NZBN: 9429031911290
We have a 30-day return policy, which means you have 30 days after receiving your item to request a return.
To be eligible for a return, your item must be in the same condition that you received it, unworn or unread.
To start a return, you can contact us at sales@bookexpress.co.nz. Please note that returns will need to be sent to the following address: 35 Nathan Terrace, Shannon, New Zealand 4821.
If your return is for a quality or incorrect item, the cost of return will be on us, and will refund your cost. If it is for a change of mind, the return will be at your cost.
You can always contact us for any return question at sales@bookexpress.co.nz.
Damages and issues
Please inspect your order upon reception and contact us immediately if the item is defective, damaged or if you receive the wrong item, so that we can evaluate the issue and make it right.
Exceptions / non-returnable items
Certain types of items cannot be returned, like perishable goods (such as food, flowers, or plants), custom products (such as special orders or personalised items), and personal care goods (such as beauty products). Although we don't currently sell anything like this. Please get in touch if you have questions or concerns about your specific item.
Unfortunately, we cannot accept returns on gift cards.
Exchanges
The fastest way to ensure you get what you want is to return the item you have, and once the return is accepted, make a separate purchase for the new item.
European Union 14 day cooling off period
Notwithstanding the above, if the merchandise is being shipped into the European Union, you have the right to cancel or return your order within 14 days, for any reason and without a justification. As above, your item must be in the same condition that you received it, unworn or unused, with tags, and in its original packaging. You’ll also need the receipt or proof of purchase.
Refunds
We will notify you once we’ve received and inspected your return, and let you know if the refund was approved or not. If approved, you’ll be automatically refunded on your original payment method within 10 business days. Please remember it can take some time for your bank or credit card company to process and post the refund too.
If more than 15 business days have passed since we’ve approved your return, please contact us at sales@bookexpress.co.nz.

