diff --git a/FestiRootkit/SysrootHook/README.md b/FestiRootkit/SysrootHook/README.md index 1643c91..d8e2f4e 100644 --- a/FestiRootkit/SysrootHook/README.md +++ b/FestiRootkit/SysrootHook/README.md @@ -1,3 +1,3 @@ -Complimentary code for this blog post: https://inino.xyz/2018/09/26/festi-rootkit-systemroot-hook/ +Complimentary code for this blog post: https://ininoxyz.wordpress.com/2018/09/26/festi-rootkit-systemroot-hook/ What it boils down to, is inserting a legacy file system filter driver in order to hide it's imagefile (KEyplorer.sys) on disk, to hide itself. See detailed blog post for further info.