MatheuZSecurity / RootkitLinks
Collection of codes focused on Linux rootkits
☆153Updated this week
Alternatives and similar repositories for Rootkit
Users that are interested in Rootkit are comparing it to the libraries listed below
Sorting:
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆121Updated 5 months ago
- ☆161Updated 6 months ago
- The result of research and investigation of malware development tricks, techniques, evasion, cryptography and linux malware☆55Updated 3 weeks ago
- Cheat sheet to detect and remove linux kernel rootkit☆72Updated 9 months ago
- Using the Counter Strike 1.6 RCON protocol as a C2 Channel.☆84Updated 7 months ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆97Updated 3 months ago
- ☆156Updated 3 months ago
- A curated compilation of extensive resources dedicated to bootkit and rootkit development.☆107Updated last month
- Windows rootkit designed to work with BYOVD exploits☆206Updated 8 months ago
- ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again.☆85Updated 6 months ago
- POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY☆216Updated 5 months ago
- ☆69Updated 7 months ago
- ☆105Updated last year
- Proof of concept & details for CVE-2025-21298☆189Updated 7 months ago
- (0day) Local Privilege Escalation in IObit Malware Fighter☆150Updated 5 months ago
- RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging☆198Updated 6 months ago
- Payload encoding utility to effectively lower payload entropy.☆119Updated 5 months ago
- Bypass user-land hooks by syscall tampering via the Trap Flag☆115Updated 3 weeks ago
- The different ways to dump lsass☆117Updated last month
- Tools for analyzing EDR agents☆249Updated last year
- Stuxnet extracted binaries by reversing & Stuxnet Rootkit Analysis☆66Updated last year
- Library that eases the use of indirect syscalls. Quite interesting AV/EDR bypass as PoC.☆155Updated last month
- Basic reverse shell in C using socket() with complete explanation☆67Updated 2 years ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆114Updated last year
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆207Updated 8 months ago
- Malleable shellcode loader written in C and Assembly utilizing direct or indirect syscalls for evading EDR hooks☆121Updated 8 months ago
- A bunch of resources to prepare for the OSEE certification, Offensive Security's hardest course.☆103Updated 3 years ago
- early cascade injection PoC based on Outflanks blog post☆230Updated 10 months ago
- ☆153Updated 4 months ago
- In-Memory Rootkit For Linux and BSD☆81Updated last month