0xMrNiko / RootKitLinks
This repository contains Loadable Kernel Modules (LKM) and LD_PRELOAD-based modules designed for penetration testing, red teaming, and security research. These tools enable advanced techniques like process hiding, syscall hooking, and runtime application manipulation.
☆15Updated 7 months ago
Alternatives and similar repositories for RootKit
Users that are interested in RootKit are comparing it to the libraries listed below
Sorting:
- BSides Prishtina 2024 Malware Development and Persistence workshop☆98Updated 4 months ago
- Attacking the cleanup_module function of a kernel module☆46Updated 3 months ago
- Early cascade injection PoC based on Outflanks blog post written in Rust☆56Updated 8 months ago
- ☆108Updated 11 months ago
- Demoting PPL anti-malware services to less than a guest user☆63Updated 8 months ago
- A stealthy, assembly-based tool for secure function address resolution, offering a robust alternative to GetProcAddress.☆73Updated last year
- A command and control framework.☆54Updated 9 months ago
- A bunch of scripts and code i wrote.☆145Updated 10 months ago
- 「⚔️」Ring 0 Rootkit for Linux Kernels x86/x86_64 5.x/6.x☆26Updated 5 months ago
- LKM rootkit for modern kernels, with DNS C2 and a simple web interface☆74Updated 2 months ago
- Another version of .NET loader provides capabilities of bypassing ETW and AMSI, utilizing VEH for syscalls and loading .NET assemblies☆47Updated 2 months ago
- Payload encoding utility to effectively lower payload entropy.☆119Updated 5 months ago
- Section-based payload obfuscation technique for x64☆64Updated last year
- ☆59Updated 5 months ago
- Using the Counter Strike 1.6 RCON protocol as a C2 Channel.☆85Updated 7 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆123Updated last month
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆103Updated 6 months ago
- A Rust PoC implementation of the Early Bird process hollowing technique, inspired by https://github.com/boku7/HOLLOW.☆30Updated 7 months ago
- Slides for COM Hijacking AV/EDR Talk on 38c3☆74Updated 9 months ago
- Indirect Syscall implementation to bypass userland NTAPIs hooking.☆84Updated last year
- Create Anti-Copy DRM Malware☆65Updated last year
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆114Updated last year
- This repo goes with the blog entry at blog.malicious.group entitled "Writing your own RDI / sRDI loader using C and ASM".☆86Updated 2 years ago
- Driver Reverse & Exploitation☆69Updated last month
- ☆146Updated 11 months ago
- Reports on Driver, LSASS and other security services mitigations☆30Updated last month
- shell code example☆62Updated this week
- Stealthy x64 thread manipulation library for calling functions inside target processes without creating remote threads or installing hook…☆55Updated last month
- Linux Sleep Obfuscation☆106Updated last year
- A collection of position independent coding resources☆94Updated 3 weeks ago