HeapAllocate / sterbenLinks
fusion (user-mode + kernel-mode) rootkit for Linux systems (x86, x86_64, ARM, MIPS)
☆9Updated 4 years ago
Alternatives and similar repositories for sterben
Users that are interested in sterben are comparing it to the libraries listed below
Sorting:
- Linux kernel module that provides remote backdoor using netfilters , file and pid hiding.☆11Updated 8 years ago
- x86_64 linux rootkit using debug registers☆52Updated 3 years ago
- Code for diskless loading of ELF Shared Library using Reflective DLL Injection☆53Updated 9 years ago
- PoC of injecting code into a running Linux process☆23Updated 5 years ago
- ☆16Updated 4 years ago
- Evasive ELF Static PIE User-Land-Exec featured in Tmpout Vol 1.☆28Updated 3 years ago
- A More Comfortable (remote) SHell with full pty support and both reverse / bindport connection mode.☆30Updated 12 years ago
- ☆33Updated 9 years ago
- Poc for ELF64 runtime infection via GOT poisoning technique by elfmaster☆29Updated 5 years ago
- ☆27Updated 5 years ago
- Example for PagedOut!☆24Updated 5 years ago
- Rootkit spotter - experimental Linux rootkit finder LKM☆30Updated 4 years ago
- Matryoshka - stacked LKM loader☆52Updated last year
- Maintain Windows Persistence with an evil Netshell Helper DLL☆12Updated 6 years ago
- GUI Application in C# to run and disassemble shellcode☆35Updated 7 years ago
- In line function hooking LKM rootkit☆51Updated 5 years ago
- Windows Application Loader Running *.Exe files in Memory against Scrylla☆21Updated 5 years ago
- Reverse Windows shell over TLS☆19Updated 9 years ago
- Extremely simple but inefficient x86-64 assembly obfuscation.☆36Updated 9 years ago
- exploit termdd.sys(support kb4499175)☆59Updated 5 years ago
- Simple LKM linux kernel rootkit (x86 / x86_64)☆23Updated 4 years ago
- A reduced functionality cli client for the imdisk ram disk driver. To be used through a backdoor like meterpreter☆22Updated 6 years ago
- Kernel mode windows NT API logger☆22Updated 5 years ago
- PoC of macho loading from memory☆56Updated 6 months ago
- Win32k Elevation of Privilege Poc☆1Updated 6 years ago
- A demo implementation of a well-known technique used by some malware to evade userland hooking, using my library: libpeconv.☆19Updated 7 years ago
- ☆36Updated 6 years ago
- A simple tool to view important DLL Characteristics and change DEP and ASLR☆44Updated 6 years ago
- Master list of all my vulnerability discoveries. Mostly 3rd party kernel drivers.☆49Updated 4 years ago
- Self-Loading Registration Free COM Functions☆11Updated 5 years ago