Stealth and Rootkits

Abhijit Mohanta, Anoop Saldanha · Apress eBooks · 2020

When malware executes, it makes several changes to the system, including creating new files, processes, registry keys, services, injecting code, and DLLs into other processes, initiating network connections, and so forth. They are called malware artifacts and indicators of compromise. There are chances that a victim of the malware infection might identify any of these malware artifacts like malicious files while browsing through the system or may observe a suspicious malware process while looking into the Task Manager.

Read the paper · More papers on PaperTik