0xMrNiko / RootKit
This repository contains Loadable Kernel Modules (LKM) and LD_PRELOAD-based modules designed for penetration testing, red teaming, and security research. These tools enable advanced techniques like process hiding, syscall hooking, and runtime application manipulation.
☆11Updated 2 months ago
Alternatives and similar repositories for RootKit:
Users that are interested in RootKit are comparing it to the libraries listed below
- ☆54Updated 5 months ago
- A collection of position independent coding resources☆68Updated 2 months ago
- A synergized Visual Studio and Rust development environment☆19Updated 2 months ago
- A BOF that suspends non-GUI threads for a target process or resumes them resulting in stealthy process silencing.☆28Updated this week
- Section-based payload obfuscation technique for x64☆59Updated 8 months ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆68Updated 5 months ago
- malleable profile generator GUI for Havoc☆55Updated last year
- ☆104Updated 5 months ago
- ☆34Updated 3 weeks ago
- Linux Sleep Obfuscation☆95Updated last year
- ShadowForge Command & Control - Harnessing the power of Zoom's API, control a compromised Windows Machine from your Zoom Chats.☆47Updated last year
- A python tool to parse and describe the contents of a raw ntSecurityDescriptor structure.☆17Updated 2 months ago
- A pure C version of SymProcAddress☆26Updated last year
- ☆21Updated last month
- NailaoLoader: Hiding Execution Flow via Patching☆20Updated last month
- 「⚔️」Ring 0 Rootkit for Linux Kernels x86/x86_64 5.x/6.x☆23Updated last week
- POC of GITHUB simple C2 in rust☆53Updated 2 months ago
- It's what all the kids are talking about☆12Updated last year
- OFFZONE 2024 Malware Persistence workshop☆19Updated 4 months ago
- ☆37Updated last month
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆29Updated 2 months ago
- in-process powershell runner for BRC4☆45Updated last year
- Lena's scripts/code/resources for malware analysis☆26Updated 10 months ago
- Cortex EDR Ransomware protection Bypass☆21Updated 2 months ago
- Exploits a flaw in Remote Desktop Plus by monitoring and decrypting temporary .rdp files in %localappdata%/Temp, revealing credentials us…☆16Updated last year
- A more reliable way of resolving syscall numbers in Windows☆48Updated last year
- ☆41Updated 3 weeks ago
- Situational Awareness script to identify how and where to run implants☆50Updated 4 months ago
- A simple C++ Windows tool to get information about processes exposing named pipes.☆37Updated last month
- Dumping LSA secrets: a story about task decorrelation☆14Updated 9 months ago