3intermute / linux_syscall_hook
system call hooking on arm64 linux via a variety of methods
☆40Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for linux_syscall_hook
- silent syscall hooking without modifying sys_call_table/handlers via patching exception handler☆116Updated 6 months ago
- tprt ollvm 反混淆 修改 binja il☆31Updated 2 months ago
- 详细说明及演示MMU相关原理及过程(用于理解Linux内核Root Kernelpatch)☆20Updated 4 months ago
- linux(android) payload module☆24Updated 10 months ago
- 内核硬件调试器模块,rootkit操作 dump☆31Updated 2 years ago
- deobfuscation BR☆35Updated 8 months ago
- ☆15Updated 3 years ago
- A simple android utility for inject so (suport arm, aarch64)☆24Updated last year
- IDA Python Script for anti ollvm-arm☆26Updated 3 years ago
- deobf tx libtprt's obfuscation☆33Updated 2 months ago
- A zygisk module that dumps so file from process memory☆36Updated last month
- A small utilities to scan process memory and search patterns using frida with a single line of command☆21Updated 3 years ago
- linux x86_64 and arm64 syscall hook☆15Updated 11 months ago
- ida 对抗 花指令, 基于 ida 7.5 sdk 编写☆17Updated 9 months ago
- Android-Syscall-Logger☆18Updated 3 years ago
- libEncryptor vm 还原的分享☆45Updated last month
- In-memory ELF shared library loading☆37Updated last year
- Format the tcg log for qemu and present it in a more intuitive form☆12Updated last year
- An approach to utilize auditd under Android 6+☆21Updated 6 years ago
- A rootkit for Android.☆44Updated 5 months ago
- Utils use to dump android ELF from memory and do some fix including the ELF section header rebuilding☆55Updated last year
- A kernel module for tracing signal☆24Updated last year
- 使用 frida stalker 实现的 trace☆21Updated last year
- 跨平台模拟执行unicorn框架基于Qemu的TCG模式(Tiny Code Generator),以无硬件虚拟化支持方式实现全系统的虚拟化,支持跨平台和架构的CPU指令模拟,本文讨论是一款笔者的实验性项目采用Windows Hypervisor Platform虚拟机模式…☆62Updated 10 months ago
- try try full features ebpf on android without Pixel 6☆21Updated 2 years ago
- 蛋蛋模拟器分析附件☆4Updated 2 years ago
- 本工具用于解决ollvm编译出来的Linux驱动文件,加载进内核会报错“please compile with -fno-common”的问题☆29Updated 3 years ago
- idaemu is an IDA Pro Plugin - use for emulating code in IDA Pro.update for ida pro 7.7☆12Updated last year
- obpo backend server written by golang☆30Updated last year