ZeroMemoryEx/Chaos-Rootkit
Now You See Me, Now You Don't observed · 2026-08-28
Health v2 · maintenance only
58/100
- Activity 83
- Release rhythm 8
- Longevity 89
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1258
- days_rel: 691
- days_push: 104
- n_releases_24m: 1
Adoption not part of the score
1061 stars · 162 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Chaos-Rootkit is an x64 Ring 0 Windows kernel rootkit written in C++ as a research project to understand kernel internals and rootkit techniques. It demonstrates process hiding via DKOM, privilege elevation, driver swapping, file access restriction, and anti-malware bypass capabilities.
Use cases
- study Windows kernel rootkit techniques
- learn DKOM process hiding internals
- research driver signature and integrity bypass methods
- understand process protection levels in Windows
- malware analysis and defense training
- explore kernel driver swapping techniques
When to choose
- you are a security researcher studying rootkit internals
- you want to learn Windows kernel programming through real examples
- you are building defensive detections against rootkit techniques
When to avoid
- you need production software or a supported tool
- you cannot legally or ethically use offensive kernel code
- you need a signed, stable driver for deployment
- you are not familiar with Windows kernel internals
Facets
library · maturity active
security reverse-engineering security operating-systems developer-tools windows cpp rootkit kernel-driver windows-kernel dkom malware-research ring-0 privilege-escalation research
4 sources
- readme: https://github.com/ZeroMemoryEx/Chaos-Rootkit · fetched 2026-08-28 · 8c570d50fcc7
- homepage: https://www.hackandhide.com/chaos-rootkit-internals-explained/ · fetched 2026-08-29 · a623f6a1de94
- site_page: https://www.hackandhide.com/about · fetched 2026-08-29 · 11bf68ecf21b
- site_page: https://www.hackandhide.com/cve-2025-68921 · fetched 2026-08-29 · 904fb830a446
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| ZeroMemoryEx/Chaos-Rootkit | main | 58 |
For agents
markdown · JSON · MCP: product_card(name="ZeroMemoryEx/Chaos-Rootkit")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem