10pから引用
---
One way to hide is to gain control of execution
- Replace system programs
- Hooks
- Callbacks
- Specialized registers
- Layered drivers
- Others
Another way to hide is to manipulate kernel data itself
- List of processes, drivers, etc.
- Handle tables
- Others