GunshipPenguin / kiteshield
Packer/Protector for x86-64 ELF binaries on Linux
☆145Updated 3 years ago
Alternatives and similar repositories for kiteshield:
Users that are interested in kiteshield are comparing it to the libraries listed below
- A simple ptrace-less shared library injector for x64 Linux☆253Updated 2 years ago
- Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.☆157Updated 2 years ago
- A utility to fix intentionally corrupted UPX packed files.☆84Updated last year
- Yet another variant of Process Hollowing☆384Updated 2 months ago
- x86 malware emulator☆215Updated last week
- A collection of LLVM transform and analysis passes to write shellcode in regular C☆370Updated last year
- A command line Windows API tracing tool for Golang binaries.☆156Updated last year
- Collection of simple anti-debugging tricks for Linux☆55Updated 6 years ago
- An example of hijacking the dynamic linker with a custom interpreter who loads and executes modular viruses☆62Updated 3 years ago
- Linux based inter-process code injection without ptrace(2)☆245Updated 7 years ago
- An ELF / PE binary packer written in pure C, made for fun☆86Updated last year
- bdvl☆113Updated 3 years ago
- PoC capable of detecting manual syscalls from usermode.☆192Updated 4 months ago
- Small tool to run ELF binaries from memory with a given process name☆162Updated 3 years ago
- Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2☆225Updated 2 years ago
- Set of antianalysis techniques found in malware☆129Updated last year
- A collection of Linux kernel rootkits found across the internet taken and put together☆73Updated 2 years ago
- This is a simple example and explanation of obfuscating API resolution via hashing☆237Updated 4 years ago
- FreshyCalls tries to make the use of syscalls comfortable and simple, without generating too much boilerplate and in modern C++17!☆327Updated 2 years ago
- msdocsviewer is a simple tool that parses Microsoft's win32 API and driver documentation to be used within IDA.☆151Updated last year
- ☆268Updated 2 years ago
- Simple 32/64-bit PEs loader.☆137Updated 6 years ago
- ☆101Updated 2 years ago
- IdaClu is a version agnostic IDA Pro plugin for grouping similar functions. Pick an existing grouping algorithm or create your own.☆157Updated 4 months ago
- Elf binary infector written in Go.☆208Updated 2 months ago
- ROPfuscator is a fine-grained code obfuscation framework for C/C++ programs using ROP (return-oriented programming).☆424Updated 10 months ago
- Native code virtualizer for x64 binaries☆473Updated 3 months ago
- Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypa…☆247Updated last year
- Reflective SO injection is a library injection technique in which the concept of reflective programming is employed to perform the loadin…☆116Updated 8 years ago
- Simple ELF runtime packer for creating self-protecting binaries☆21Updated last year