GunshipPenguin / kiteshield
Packer/Protector for x86-64 ELF binaries on Linux
☆143Updated 3 years ago
Alternatives and similar repositories for kiteshield:
Users that are interested in kiteshield are comparing it to the libraries listed below
- A simple ptrace-less shared library injector for x64 Linux☆253Updated last year
- An example of hijacking the dynamic linker with a custom interpreter who loads and executes modular viruses☆61Updated 2 years ago
- An ELF / PE binary packer written in pure C, made for fun☆80Updated 9 months ago
- A utility to fix intentionally corrupted UPX packed files.☆82Updated last year
- A tool that is used to hunt vulnerabilities in x64 WDM drivers☆167Updated last year
- Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.☆154Updated 2 years ago
- Collection of simple anti-debugging tricks for Linux☆57Updated 6 years ago
- x86 malware emulator☆207Updated this week
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆224Updated 2 years ago
- Tiny loaders for various binary formats.☆228Updated 8 years ago
- Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypa…☆240Updated last year
- Yet another variant of Process Hollowing☆357Updated 10 months ago
- Elf binary infector written in Go.☆206Updated last week
- A custom ELF linker/loader for installing ET_REL binary patches at runtime☆153Updated 3 months ago
- A library to develop kernel level Windows payloads for post HVCI era☆380Updated 3 years ago
- Bindings for Microsoft WinDBG TTD☆217Updated last year
- A generic UEFI bootkit used to achieve initial usermode execution. It works with modifications.☆406Updated last year
- ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).☆422Updated 8 months ago
- LLVM plugin to transparently apply stack spoofing and indirect syscalls to Windows x64 native calls at compile time.☆264Updated last year
- ☆139Updated last year
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆148Updated last year
- Unlicensed tiny / small portable implementation of 128/256-bit AES encryption in C, x86, AMD64, ARM32 and ARM64 assembly☆121Updated 4 months ago
- Abusing exceptions for code execution.☆108Updated last year
- A collection of LLVM transform and analysis passes to write shellcode in regular C☆370Updated last year
- bdvl☆111Updated 2 years ago
- GhostWriting Injection Technique.☆166Updated 6 years ago
- Set of antianalysis techniques found in malware☆129Updated last year
- A command line Windows API tracing tool for Golang binaries.☆156Updated last year
- Converted phnt (Native API header files from the System Informer project) to IDA TIL, IDC (Hex-Rays).☆124Updated 4 months ago
- Reverse engineered source code of the autochk rootkit☆199Updated 5 years ago