DEF CON 33 - Infecting the Boot to Own the Kernel - Alejandro Vazquez, Maria San Jose @DEFCONConference
DEF CON 33 - Infecting the Boot to Own the Kernel - Alejandro Vazquez, Maria San Jose  @DEFCONConference
Uploaded October 2025 | Updated September 2026, 3 weeks ago
Bootkits and Rootkits represent some of the most complex and stealthy forms of malware, capable of achieving full system control before and after the OS is loaded. While often discussed in theory, their actual construction, interaction, and execution flow remain mostly hidden from public view. This talk sheds light on how these implants are built and how their components interact across boot stages and kernel space.

We'll explore the internals of a fully functional UEFI Bootkit and Kernel-mode Rootkit, examining their modular design, runtime interactions, and the mechanisms used to hook critical parts of the Windows boot chain. Attendees will see how these implants operate across pre-boot and post-boot phases, including early internet connectivity from firmware, dynamic payload delivery, runtime service hooking, deep kernel control, and advanced capabilities like hiding files, processes, and network activity, blocking traffic, capturing keystrokes, and maintaining command and control directly from kernel space.

Everything shown on stage will be yours to explore: a complete Bootkit and Rootkit framework, fully customizable and ready to simulate real threats, test defenses, or build something even stealthier.
DEF CON 33 - Infecting the Boot to Own the Kernel - Alejandro Vazquez, Maria San JoseDEF CON 33 - Unveiling the  Perils of the TorchScript Engine in PyTorch - Jian Zhou, Lishuo SongDEF CON 33 - DC101 Panel - Alethe Denis, Nikita Kronenberg , zziks, Nicole Schwartz, Nina AlliDEF CON 32 - Locksport Competitions: Compete in the Olympics of Locks  -Matt BurroughDEF CON 33 - Preventing One of The Largest Supply-Chain Attacks in History - Maksim ShudrakDEF CON 33 - Hacking Context for Auto Root Cause and Attack Flow Discovery - Ezz TahounDEF CON 33 - Gateways to Chaos - How We Proved Modems Are a Ticking Time Bomb - Chiao-Lin  YuDEF CON 3 3 - Exploiting Vulns in EV Charging Comms - Jan Berens, Marcell Szakály, Sebastian KöhlerDEF CON 32 - Social Engineering Like you’re Picard - Jayson E  StreetDEF CON 32 - Encrypted newspaper ads in the 19th century - Elonka Dunin, Klaus SchmehDEF CON 32 - Physical OSINT - Lukas McCulloughDEF CON 33 - Building the first open source hackable Quantum Sensor - Mark Carney, Victoria  Kumaran
DEFCONConference |

DEF CON 33 - Infecting the Boot to Own the Kernel - Alejandro Vazquez, Maria San Jose

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER