MatheuZSecurity / RootkitLinks
Collection of codes focused on Linux rootkits
☆187Updated last month
Alternatives and similar repositories for Rootkit
Users that are interested in Rootkit are comparing it to the libraries listed below
Sorting:
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆132Updated 7 months ago
- Stealthy Linux Kernel Rootkit for modern kernels (6x)☆560Updated this week
- Cheat sheet to detect and remove linux kernel rootkit☆75Updated 11 months ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆117Updated 6 months ago
- ☆164Updated 9 months ago
- The result of research and investigation of malware development tricks, techniques, evasion, cryptography and linux malware☆63Updated last month
- Shellcode IDE — makes developing and analyzing shellcode much more convenient.☆106Updated 3 weeks ago
- Using the Counter Strike 1.6 RCON protocol as a C2 Channel.☆87Updated 9 months ago
- ☆201Updated last week
- ☆157Updated 6 months ago
- POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY☆224Updated 8 months ago
- Windows rootkit designed to work with BYOVD exploits☆211Updated 10 months ago
- Tools for analyzing EDR agents☆271Updated last year
- Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.☆349Updated 3 months ago
- Payload encoding utility to effectively lower payload entropy.☆119Updated 7 months ago
- ☆154Updated 7 months ago
- ☆105Updated last year
- Proof of concept & details for CVE-2025-21298☆191Updated 10 months ago
- RunPE implementation with multiple evasive techniques☆251Updated 2 months ago
- ☆71Updated 10 months ago
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆332Updated this week
- ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again.☆88Updated 9 months ago
- Comprehensive Windows Syscall Extraction & Analysis Framework☆153Updated 3 months ago
- Stuxnet extracted binaries by reversing & Stuxnet Rootkit Analysis☆76Updated last year
- ( 0day ) Local Privilege Escalation in IObit Malware Fighter☆162Updated 8 months ago
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆161Updated 4 months ago
- RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging☆203Updated 9 months ago
- Basic reverse shell in C using socket() with complete explanation☆67Updated 2 years ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆117Updated last year
- A curated compilation of extensive resources dedicated to bootkit and rootkit development.☆158Updated 4 months ago