Released part III of my anti anti rootkit series recently. I showcase a way to implement a 'threadless' rootkit by using a spin on the .data pointer hijacking technique known from kernel game cheats.
This part concludes the trilogy, but theres more to come ;)
eversinc33.com/posts/anti-a...