0xMrNiko / RootKitLinks
This repository contains Loadable Kernel Modules (LKM) and LD_PRELOAD-based modules designed for penetration testing, red teaming, and security research. These tools enable advanced techniques like process hiding, syscall hooking, and runtime application manipulation.
☆12Updated 5 months ago
Alternatives and similar repositories for RootKit
Users that are interested in RootKit are comparing it to the libraries listed below
Sorting:
- A synergized Visual Studio and Rust development environment☆18Updated 5 months ago
- Linux Sleep Obfuscation☆103Updated last year
- ☆57Updated 2 months ago
- LKM rootkit for modern kernels, with DNS C2 and a simple web interface☆72Updated last week
- Unhook Ntdll.dll, Go & C++.☆25Updated 2 months ago
- Section-based payload obfuscation technique for x64☆64Updated 11 months ago
- Post-Ex BOF tooling for Hannibal☆24Updated 7 months ago
- A more reliable way of resolving syscall numbers in Windows☆51Updated last year
- Reports on Driver, LSASS and other security services mitigations☆24Updated last week
- shell code example☆57Updated 2 months ago
- Shellcode Loader Utilizing ETW Events☆63Updated 4 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆14Updated 2 years ago
- various methods of making API calls☆17Updated 5 months ago
- a demo module for the kaine agent to execute and inject assembly modules☆39Updated 10 months ago
- Attacking the cleanup_module function of a kernel module☆37Updated 2 weeks ago
- A C#-implemented malware that dynamically modifies its own hash upon each execution to evade detection.☆13Updated 5 months ago
- Windows AppLocker Driver (appid.sys) LPE☆62Updated 11 months ago
- A truly Position Independent Code (PIC) NimPlant C2 beacon written in C, without reflective loading.☆61Updated 5 months ago
- A process injection technique using only thread context manipulation☆38Updated last year
- Combining 3 techniques (Threadless Injection + DLL Stomping + Caro-Kann) together to evade MDE.☆61Updated last year
- BOF for C2 framework☆41Updated 8 months ago
- Template-based generation of shellcode loaders☆78Updated last year
- NailaoLoader: Hiding Execution Flow via Patching☆20Updated 4 months ago
- yet another sleep encryption thing. also used the default github repo name for this one.☆69Updated 2 years ago
- Rootkit for the blue team. Sophisticated and optimized LKM to detect and prevent malicious activity☆35Updated last year
- Proof-of-concept kernel driver that hijacks the Windows kernel extension table mechanism to preserve process notify callbacks even when a…☆80Updated last week
- converts sRDI compatible dlls to shellcode☆29Updated 5 months ago
- https://github.com/janoglezcampos/c_syscalls with the ASM rewritten by myself for Visual Studio's Compiler.☆31Updated last year
- POC of GITHUB simple C2 in rust☆53Updated 5 months ago
- Win32 keylogger that supports all (non-ime using) languages correctly☆50Updated last year