Aviral2642 / kernelghostLinks
KernelGhost is a next-generation offensive security framework that combines stealthy eBPF-based rootkit capabilities with advanced hypervisor escape techniques. It enables persistent cross-VM access, stealth process hiding, UEFI firmware backdoors, and more all while evading modern detection systems.
☆14Updated 4 months ago
Alternatives and similar repositories for kernelghost
Users that are interested in kernelghost are comparing it to the libraries listed below
Sorting:
- Kernel-based Process Monitoring on Linux Endpoints for File System, TCP and UDP Networking Events and optionally DNS, HTTP and SYSLOG App…☆67Updated 3 months ago
- A simple mitmproxy blueprint to intercept HTTPS traffic from app running on Kubernetes☆71Updated 3 months ago
- ☆81Updated 3 weeks ago
- DevGuard Backend - Secure your Software Supply Chain - Attestation-based compliance as Code, manage your CVEs seamlessly, Integrate your …☆77Updated last week
- Publications from the eBPF foundation☆23Updated 8 months ago
- A toy containers aware firewall built in Rust☆23Updated 2 years ago
- ☆89Updated last year
- Threat Modeling (based on STRIDE approach) for Kubernetes systems.☆25Updated 9 months ago
- ☆64Updated 2 years ago
- Protect your Cloud Native Applications running on Kubernetes from malicious attacks with pre-registered source code, pre-registered runti…☆56Updated 7 months ago
- Simple root privilege escalation detection using eBPF 🐝☆13Updated 6 months ago
- Kubernetes offensive framework built in eBPF☆37Updated 2 years ago
- ☆21Updated 2 months ago
- Simple ethernet interface traffic monitor and reporting tool☆86Updated last week
- VMClarity is a tool for agentless detection and management of Virtual Machine Software Bill Of Materials (SBOM) and vulnerabilities☆102Updated 9 months ago
- NamespaceHound is the tool for detecting the risk of potential namespace crossing violations in multi-tenant clusters.☆107Updated 7 months ago
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆29Updated 5 months ago
- ☆90Updated 2 months ago
- Jibril: A performant and low impact Linux runtime security tool agent.☆13Updated 2 months ago
- ☆42Updated 2 months ago
- This tool have the power to hide any PID/directory in the Linux kernel☆28Updated 10 months ago
- Sniff and attack networks that use IP-in-IP or VXLAN encapsulation protocols.☆22Updated 11 months ago
- K8s API Honeypot with Active Defense Capabilities☆42Updated last year
- Leaky Vessels Dynamic Detector☆102Updated 3 months ago
- Linux Process Discovery. C Library, Go bindings, Runtime.☆222Updated 3 years ago
- Kubernetes Unhinged Shell 😎☆46Updated 2 years ago
- Outil de sécurité des architectures kubernetes avancées☆54Updated last month
- Demo repository for running eBPF in GitHub Actions☆19Updated 4 months ago
- Use eBPF to inject chaos into local processes☆65Updated 10 months ago
- Adversary emulation for EDR/SIEM testing (macOS/Linux)☆49Updated 2 weeks ago