Acceis / eBPF-hide-PIDLinks
This tool have the power to hide any PID/directory in the Linux kernel
☆29Updated 10 months ago
Alternatives and similar repositories for eBPF-hide-PID
Users that are interested in eBPF-hide-PID are comparing it to the libraries listed below
Sorting:
- Rust Linux Kernel Module designed for LKM rootkit detection☆50Updated 4 months ago
- kubernetes rootkit☆31Updated last year
- ☆89Updated last year
- eBPF hacks☆187Updated 7 months ago
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆120Updated 2 months ago
- A collection of projects demonstrating various commandline cloaking techniques on Linux☆59Updated 3 years ago
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆164Updated 11 months ago
- WallEscape vulnerability in util-linux☆51Updated last year
- Open Source eBPF Malware Analysis Framework☆48Updated 9 months ago
- A simple Meterpreter stager written in Rust.☆38Updated 10 months ago
- Use eBPF to inject chaos into local processes☆65Updated 10 months ago
- Monarch - The Adversary Emulation Toolkit☆62Updated 7 months ago
- Dump Linux keyrings☆20Updated last year
- Userland exec PoC to be used as attack vector technique☆85Updated 6 months ago
- A collection of bypasses and exploits for eBPF-based cloud security.☆24Updated last year
- Kubernetes offensive framework built in eBPF☆37Updated 2 years ago
- PoC and Detection for CVE-2024-21626☆75Updated last year
- An eBPF detection program for CVE-2022-0847☆28Updated 3 years ago
- Dll hijack -- just one macro☆12Updated 2 years ago
- A swiss army knife tool for running, injecting and organizing your BOFs collection☆61Updated 3 weeks ago
- Attacking the cleanup_module function of a kernel module☆39Updated last month
- Signing-key abuse and update exploitation framework☆130Updated 2 months ago
- Speedy probe-based UDP service scanner☆92Updated last month
- Rust out-of-tree Linux Kernel Modules (LKMs) experimentation framework☆47Updated 2 years ago
- Post-exploit a compromised etcd, gain persistence and remote shell to nodes.☆80Updated last year
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆133Updated 2 years ago
- nysm is a stealth post-exploitation container.☆254Updated last month
- dlopen() filelessly a shared object or even a program (and run it).☆55Updated last year
- ☆31Updated 2 years ago
- Pure Go rewrite of knockknock☆10Updated 2 years ago