DualHorizon / blackpill
A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs
☆268Updated 2 months ago
Alternatives and similar repositories for blackpill:
Users that are interested in blackpill are comparing it to the libraries listed below
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆88Updated last month
- Collection of codes focused on Linux rootkits☆91Updated 2 weeks ago
- ☆224Updated 2 months ago
- nysm is a stealth post-exploitation container.☆244Updated last year
- A new technique that can be used to bypass memory scanners. This can be useful in hiding problematic code (such as reflective loaders imp…☆298Updated 5 months ago
- ROP-based sleep obfuscation to evade memory scanners☆332Updated last month
- Evasion by machine code de-optimization.☆370Updated 7 months ago
- Freeze.rs is a payload toolkit for bypassing EDRs using suspended processes, direct syscalls written in RUST☆179Updated 5 months ago
- Nameless C2 - A C2 with all its components written in Rust☆262Updated 5 months ago
- eBPF hacks☆183Updated 3 months ago
- Tools for analyzing EDR agents☆221Updated 9 months ago
- Apply a divide and conquer approach to bypass EDRs☆279Updated last year
- A command and control framework written in rust.☆311Updated 2 weeks ago
- Proof of Concept for manipulating the Kernel Callback Table in the Process Environment Block (PEB) to perform process injection and hijac…☆205Updated 4 months ago
- Collect Windows telemetry for Maldev☆312Updated last month
- Evasive shellcode loader☆346Updated 4 months ago
- Slides and files for the Reversing Rust Binaries: One step beyond strings workshop at REcon 2024, presented on June 28, 2024.☆75Updated 8 months ago
- Open Source C&C Specification☆239Updated last week
- Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)☆239Updated 8 months ago
- ☆296Updated 4 months ago
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆192Updated 2 months ago
- Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.☆229Updated last year
- Payload encoding utility to effectively lower payload entropy.☆110Updated 3 months ago
- Some Rust program I wrote while learning Malware Development☆127Updated last month
- Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypa…☆246Updated last year
- Encrypted shellcode Injection to avoid Kernel triggered memory scans☆365Updated last year
- A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTA…☆227Updated 2 months ago
- Template-based shellcode packer written in Rust, with indirect syscall support. Made with <3 for pentesters.☆265Updated 7 months ago
- Simulate the behavior of AV/EDR for malware development training.☆501Updated last year