Hackerl / pangolin
Inject ELF into remote process
☆129Updated last year
Alternatives and similar repositories for pangolin:
Users that are interested in pangolin are comparing it to the libraries listed below
- The demo of hidden process and ko module☆13Updated 2 years ago
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆284Updated last month
- Low-level RASP: Protecting Applications Implemented in High-level Programming Languages☆57Updated last year
- a PoC for Linux to get around agents that log commands being executed, without root privilege. Linux低权限模糊化执行的程序名和参数,避开基于execve系统调用监控的命令日志☆240Updated 5 years ago
- HIDS/EDR Demo☆15Updated 4 years ago
- S&P2023 Paper☆39Updated 2 years ago
- Linux EDR written in Golang and based on eBPF.☆232Updated 2 years ago
- 40行代码检 测到大部分CobaltStrike的shellcode☆272Updated 3 years ago
- ☆81Updated 2 years ago
- Container (Docker) escape exploits☆50Updated 3 years ago
- 一个基于LKM的Linux内核级rootkit的实现,包含模块隐藏、提权、文件隐藏、进程隐藏、端口隐藏功能☆71Updated 10 months ago
- CVE-2022-0185 POC and Docker and Analysis write up☆37Updated 2 years ago
- SysTracer: Linux 系统活动跟踪器☆31Updated 2 years ago
- ☆50Updated 2 years ago
- ☆46Updated 2 years ago
- IDA Pro每周小技巧☆273Updated 2 years ago
- CVE exploits for Web, Windows, Linux and others are independently written by Zhuri Lab☆48Updated 4 years ago
- Hades is an cross-platform HIDS with kernel-space data collection.☆44Updated last year
- Elkeid HUB is a rule/event processing engine maintained by the Elkeid Team that supports streaming/offline (not yet supported by the comm…☆93Updated last year
- Linux下应用层注入/hook技术实现端口复用☆1Updated 3 years ago
- Auto-generated CodeQL rules for matching CVE vulnerabilities and variants.☆156Updated 3 months ago
- 通过Linux netlink NETLINK_CONNECTOR 协议实时进行监控本机进程情况。☆13Updated 5 years ago
- ☆22Updated 5 years ago
- codemillx is a tool for CodeQL, extract the comments in the code and generate codeql module. 强化Go开源项目安全检测(内含开源项目漏洞挖掘方法)☆207Updated 2 years ago
- Go语言,不允许import,请开始你的表演☆65Updated 2 years ago
- 容器安全漏洞的分析与复现☆151Updated 9 months ago
- CVE-2021-1732 Microsoft Windows 10 本地提权漏 研究及Poc/Exploit开发☆81Updated 3 years ago
- Use java instrument API without JAR file☆44Updated 2 years ago
- ☆23Updated 2 years ago
- CVE-2022-0847 used to achieve container escape 利用CVE-2022-0847 (Dirty Pipe) 实现容器逃逸☆31Updated 2 years ago