MatheuZSecurity / Rootkit
Collection of codes focused on Linux rootkits
☆107Updated 2 months ago
Alternatives and similar repositories for Rootkit:
Users that are interested in Rootkit are comparing it to the libraries listed below
- Cheat sheet to detect and remove linux kernel rootkit☆57Updated 4 months ago
- ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again.☆79Updated 2 months ago
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆103Updated 3 weeks ago
- ☆67Updated 3 months ago
- Basic reverse shell in C using socket() with complete explanation☆65Updated last year
- The result of research and investigation of malware development tricks, techniques, evasion, cryptography and linux malware☆42Updated last month
- ☆105Updated 9 months ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆109Updated 8 months ago
- Using the Counter Strike 1.6 RCON protocol as a C2 Channel.☆78Updated 2 months ago
- Stuxnet extracted binaries by reversing & Stuxnet Rootkit Analysis☆52Updated 7 months ago
- POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY☆187Updated 3 weeks ago
- Windows Persistence IT-Security☆97Updated last month
- Windows rootkit designed to work with BYOVD exploits☆198Updated 3 months ago
- Stage 0☆159Updated 4 months ago
- Command and Control (C2) framework☆126Updated last year
- Aplos an extremely simple fuzzer for Windows binaries.☆68Updated 2 months ago
- Local & remote Windows DLL Proxying☆164Updated 10 months ago
- RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging☆186Updated 2 months ago
- MIPS VM to execute payloads without allocating executable memory. Based on a PlayStation 1 (PSX) Emulator.☆113Updated 5 months ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆80Updated this week
- CVE-2024-30090 - LPE PoC☆106Updated 6 months ago
- ☆37Updated 4 months ago
- A curated compilation of extensive resources dedicated to bootkit and rootkit development.☆47Updated 2 weeks ago
- Tools for analyzing EDR agents☆228Updated 10 months ago
- Windows Kernel Pool (clfs.sys) Corruption Privilege Escalation☆127Updated last year
- Lena's scripts/code/resources for malware analysis☆26Updated 10 months ago
- ☆105Updated 6 months ago
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆103Updated last month
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆92Updated last week
- PoC for using MS Windows printers for persistence / command and control via Internet Printing☆148Updated last year