I didn't start RVBBIT with the idea of building a security framework.

It was much simpler than that.

I wanted to understand Linux rootkits beyond reading about them.

I had been studying techniques such as syscall hooking, DKOM, process hiding and kernel module hiding separately, and at some point I realized that reading another explanation wasn't going to answer the questions I had.

I wanted to see what happened when these techniques actually lived together.