MatheuZSecurity / ElfDoor-gcc
ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.
☆92Updated last week
Alternatives and similar repositories for ElfDoor-gcc:
Users that are interested in ElfDoor-gcc are comparing it to the libraries listed below
- ☆105Updated 5 months ago
- Windows rootkit designed to work with BYOVD exploits☆183Updated 3 months ago
- "Service-less" driver loading☆151Updated 4 months ago
- ☆140Updated 5 months ago
- ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again.☆75Updated last month
- LKM rootkit for modern kernels, with DNS C2 and a simple web interface☆65Updated 2 weeks ago
- Malleable shellcode loader written in C and Assembly utilizing direct or indirect syscalls for evading EDR hooks☆105Updated 4 months ago
- POC of GITHUB simple C2 in rust☆53Updated 2 months ago
- In-Memory Rootkit For Linux☆69Updated 2 months ago
- Collection of codes focused on Linux rootkits☆106Updated last month
- Attacking the cleanup_module function of a kernel module☆30Updated 3 weeks ago
- A Mythic Agent written in PIC C.☆186Updated 2 months ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆109Updated 7 months ago
- Payload encoding utility to effectively lower payload entropy.☆116Updated last week
- Shellcode encryptor using a substitution cipher with a randomly generated key.☆126Updated 3 months ago
- Sleep obfuscation☆216Updated 4 months ago
- BOF that finds all the Nt* system call stubs within NTDLL and overwrites with clean syscall stubs (user land hook evasion)☆173Updated 2 months ago
- CVE-2024-30090 - LPE PoC☆106Updated 6 months ago
- ☆34Updated 11 months ago
- RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging☆183Updated last month
- ☆39Updated last year
- Using the Counter Strike 1.6 RCON protocol as a C2 Channel.☆78Updated 2 months ago
- Stage 0☆156Updated 4 months ago
- 「🧊」Ring 3 Rootkit for Windows 10☆57Updated 4 months ago
- ☆39Updated last month
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆92Updated last week
- Make an Linux Kernel rootkit visible again.☆50Updated last month
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated last year
- ☆54Updated 6 months ago
- Automated .NET AppDomain hijack payload generation☆123Updated 2 months ago