01

WhiteLotus

COMPLETED
LANG C UEFIBootkitx64Windows

UEFI DXE bootkit targeting x64 Windows systems. Survives OS reinstalls by persisting in the EFI System Partition.

02

SSDT Hook Detector

COMPLETED
LANG C WindowsKernelSSDTRootkit Detection

User-mode tool that reads the SSDT from kernel memory and detects hooked syscalls by comparing function pointers against ntoskrnl.exe's expected base range.