Skip to main content

EPIROOTKIT

Welcome to the official Epirootkit documentation. The purpose of this documentation is to centralize all the information necessary to set up the rootkit and understand how it works.

warning

This project is for educational use only and should only be used with the explicit consent of the owner of the computer on which you want to install the module. The authors of the project would not be held responsible in case of misuse.

What's in this documentation

  • Getting Started — Set up the test VM, install and uninstall the rootkit.
  • How It Works — Understand the internal architecture, the C2 connection, privilege escalation, command execution, authentication, and debug mode.
  • Attacker UI — Set up and use the WLKOM C2 web interface to control the rootkit remotely.

Technical documentation

The Doxygen-generated API reference is available separately: Technical documentation