HVM- going into details http://www.rootkit.com//newsread.php?newsid=1006 Kernel Sockets Module based on TDI and WSK - updated http://www.rootkit.com//newsread.php?newsid=1002 Nostalgia: n00bk1t, an advanced ring3 rootkit in C http://www.rootkit.com//newsread.php?newsid=1000 TDL3 - Why so serious? Let's put a smile on that face .. http://www.rootkit.com//newsread.php?newsid=979 Access token stealing on Windows http://www.rootkit.com//newsread.php?newsid=969 One safe hook handler - E8 Method, paper http://www.rootkit.com//newsread.php?newsid=960 Network Programming Interface of Windows Vista/2008: internals, using and hacking http://www.rootkit.com//newsread.php?newsid=952 Implementing SMM PS/2 Keyboard sniffer http://www.rootkit.com//newsread.php?newsid=945 Windows Auxiliary API library - Internals http://www.rootkit.com//newsread.php?newsid=930 CodeWalker: Another AntiRootkit Tool http://www.rootkit.com//newsread.php?newsid=926 Interrupt Descriptor table explained. http://www.rootkit.com//newsread.php?newsid=928 Hide your SSDT hooks http://www.rootkit.com//newsread.php?newsid=922 How Memory Analysis Works to Perform Integrity Checking http://www.rootkit.com//newsread.php?newsid=920 CsrWalker - using csrss as rkdetector http://www.rootkit.com//newsread.php?newsid=908 Rootkit Unhooker v3.8 It's Past, Present and Future of the NTx86 Rootkit Detection http://www.rootkit.com//newsread.php?newsid=902