MS Research has published some papers about Rootkit technologies and especially RootKit detection: http://research.microsoft.com/rootkit/ This stuff is VERY GOOD to read, and has been positively commented by a lot of people, including Bruce Schneier: