Aviral2642 / kernelghostLinks
KernelGhost is a next-generation offensive security framework that combines stealthy eBPF-based rootkit capabilities with advanced hypervisor escape techniques. It enables persistent cross-VM access, stealth process hiding, UEFI firmware backdoors, and more all while evading modern detection systems.
☆16Updated 7 months ago
Alternatives and similar repositories for kernelghost
Users that are interested in kernelghost are comparing it to the libraries listed below
Sorting:
- ☆63Updated 2 years ago
- ☆85Updated 3 weeks ago
- ☆89Updated last year
- Kernel-based Process Monitoring on Linux Endpoints for File System, TCP and UDP Networking Events and optionally DNS, HTTP and SYSLOG App…☆70Updated 7 months ago
- Threat Modeling (based on STRIDE approach) for Kubernetes systems.☆25Updated last year
- Simple root privilege escalation detection using eBPF 🐝☆35Updated last month
- Protect your Cloud Native Applications running on Kubernetes from malicious attacks with pre-registered source code, pre-registered runti…☆57Updated 11 months ago
- A simple mitmproxy blueprint to intercept HTTPS traffic from app running on Kubernetes☆73Updated 7 months ago
- This tool have the power to hide any PID/directory in the Linux kernel☆30Updated last year
- ☆27Updated 6 months ago
- An eBPF-based traffic obfuscation system that try to disguises WireGuard protocol traffic to bypass DPI and government censorship☆28Updated this week
- Sniff and attack networks that use IP-in-IP or VXLAN encapsulation protocols.☆23Updated last year
- Post-Quantum Cryptography Scanner - Scan SSH/TLS servers for PQC support☆92Updated last week
- Leaky Vessels Dynamic Detector☆103Updated 7 months ago
- Simple ethernet interface traffic monitor and reporting tool☆88Updated last month
- Kubernetes offensive framework built in eBPF☆39Updated 2 years ago
- Publications from the eBPF foundation☆28Updated 2 months ago
- SnailLoad Demo Webserver☆38Updated 9 months ago
- Spotter is a comprehensive Kubernetes security scanner that uses CEL-based rules to identify security vulnerabilities, misconfigurations,…☆65Updated 2 months ago
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆30Updated 9 months ago
- AxoSyslog - the scalable security data processor☆98Updated this week
- Signing-key abuse and update exploitation framework☆131Updated 6 months ago
- Pwning IPv6 Networks☆37Updated 3 weeks ago
- VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities☆103Updated last year
- Jibril: A performant and low impact Linux runtime security tool agent.☆13Updated 5 months ago
- Demo repository for running eBPF in GitHub Actions☆23Updated 7 months ago
- ☆89Updated 2 weeks ago
- Open Source runtime tool which help to detect malware code execution and run time mis-configuration change on a kubernetes cluster☆37Updated 3 years ago
- A toy containers aware firewall built in Rust☆23Updated 2 years ago
- Containerlab topologies for routing software interoperability tests.☆15Updated last month