3intermute / linux_syscall_hook
system call hooking on arm64 linux via a variety of methods
☆44Updated 2 years ago
Alternatives and similar repositories for linux_syscall_hook:
Users that are interested in linux_syscall_hook are comparing it to the libraries listed below
- silent syscall hooking without modifying sys_call_table/handlers via patching exception handler☆124Updated 8 months ago
- 详细说明及演示MMU相关原理及过程(用于理解Linux内核Root Kernelpatch)☆21Updated 7 months ago
- tprt ollvm 反混淆 修改 binja il☆35Updated 4 months ago
- a simple project that uses Frida+QBDI to do tricks like JNI_OnLoad tracing on Android(AArch64).☆19Updated last year
- 内核硬件调试器模块,rootkit操作 dump☆34Updated 2 years ago
- A rootkit for Android.☆47Updated 7 months ago
- In-memory ELF shared library loading☆37Updated 2 years ago
- A simple android utility for inject so (suport arm, aarch64)☆24Updated last year
- deobfuscation BR☆38Updated 10 months ago
- 跨平台模拟执行unicorn框架基于Qemu的TCG模式(Tiny Code Generator),以无硬件虚拟化支持方式实现全系统的虚拟化,支持跨平台和架构的CPU指令模拟,本文讨论是一款笔者的实验性项目采用Windows Hypervisor Platform虚拟机模式…☆65Updated last year
- Kotoamatsukami is an obfuscator based on LLVM-17, utilizing LLVM's new pass to implement plug-in features, for obfuscating multiple langu…☆24Updated this week
- ☆15Updated 3 years ago
- 本工具用于解决ollvm编译出来的Linux驱动文件,加载进内核会报错“please compile with -fno-common”的问题☆30Updated 3 years ago
- 反ida内联汇编花指令☆49Updated last year
- linux x86_64 and arm64 syscall hook☆18Updated last year
- A GKI Android kernel driver(ARMv8.3) template compiled by llvm-msvc☆33Updated 8 months ago
- fork 自 https://gitlab.com/eshard/d810 添加了参考文章、测试样本,作为备份。☆12Updated 3 years ago
- 使用 frida stalker 实现的 trace☆24Updated 2 years ago
- A kernel module for tracing signal☆27Updated 2 years ago
- Simple Android ARM&ARM64 GOT Hook☆34Updated 2 years ago
- A zygisk module that dumps so file from process memory☆46Updated 3 months ago
- Format the tcg log for qemu and present it in a more intuitive form☆12Updated last year
- An approach to utilize auditd under Android 6+☆21Updated 6 years ago
- android app native so fuzz. efficiently run in a real machine with frida environment. See Background: https://idhyt.blogspot.com/2020/02/…☆39Updated last year
- try try full features ebpf on android without Pixel 6☆21Updated 2 years ago
- obpo backend server written by golang☆32Updated last year
- A program to read and modify the memory of other processes.☆16Updated last year
- monitor svc calls of android☆72Updated 6 years ago
- Taint Analysis Engine and Trace Exploration : Overcome Obfuscation☆31Updated 2 months ago