Gui774ume / ebpfkitLinks
ebpfkit is a rootkit powered by eBPF
☆821Updated 2 years ago
Alternatives and similar repositories for ebpfkit
Users that are interested in ebpfkit are comparing it to the libraries listed below
Sorting:
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆673Updated last year
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,912Updated last year
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆139Updated 2 years ago
- Linux Kernel Runtime Integrity with eBPF☆183Updated 2 years ago
- An eBPF playground☆209Updated last year
- Linux Kernel Hacking☆746Updated last year
- A Linux Host-based Intrusion Detection System based on eBPF.☆453Updated last year
- ☆309Updated 2 years ago
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆302Updated last year
- BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for em…☆461Updated last week
- Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.☆1,647Updated 2 years ago
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆293Updated this week
- ☆468Updated last month
- CVE-2022-23222: Linux Kernel eBPF Local Privilege Escalation☆578Updated 3 years ago
- bpflock - eBPF driven security for locking and auditing Linux machines☆150Updated 3 years ago
- Red-Team LKM☆618Updated last month
- Dectect syscall hooking using eBPF☆165Updated 2 years ago
- Linux EDR written in Golang and based on eBPF.☆244Updated 3 years ago
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆167Updated last year
- Credentials Dumper for Linux using eBPF☆1,152Updated last year
- Linux Kernel hooking engine (x86)☆376Updated last month
- The BTFhub Archive repository provides BTF files for those published kernels that lack native support for embedded BTF, thereby enhancing…☆125Updated 3 weeks ago
- A file system events notifier based on eBPF☆73Updated 2 years ago
- Redress - A tool for analyzing stripped Go binaries☆1,126Updated 3 weeks ago
- Get live information about applications that make network requests (based on eBPF)☆53Updated 2 months ago
- Generate eBPF programs and tracing with ChatGPT☆265Updated 4 months ago
- A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.☆872Updated 8 months ago
- GoRE - Package gore is a library for analyzing Go binaries☆518Updated 2 weeks ago
- Go symbol recovery tool☆857Updated this week
- linux elf injector for x86 x86_64 arm arm64☆342Updated 7 years ago