Stealthy Linux Kernel Rootkit for modern kernels (6x)
☆1,697Jun 11, 2026Updated 2 weeks ago
Alternatives and similar repositories for Singularity
Users that are interested in Singularity are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Attacking the cleanup_module function of a kernel module☆58Jun 30, 2025Updated last year
- A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs☆341Feb 27, 2026Updated 4 months ago
- Collection of codes focused on Linux rootkits☆213Oct 22, 2025Updated 8 months ago
- Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.☆382Aug 29, 2025Updated 10 months ago
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆134Apr 13, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- BeaconatorC2 is a framework for red teaming and adversarial emulation, providing a full-featured management interface, along with a catal…☆95May 25, 2026Updated last month
- DSCourier is a proof-of-concept that uses the WinGet Configuration COM API to apply DSC configurations through Microsoft-signed binaries.☆206Updated this week
- Windows rootkit designed to work with BYOVD exploits☆223Jan 18, 2025Updated last year
- Make an Linux Kernel rootkit visible again.☆60Feb 27, 2025Updated last year
- Red-Team LKM☆649May 31, 2026Updated last month
- Using Chromium-based browsers as a proxy for C2 traffic.☆153Dec 6, 2025Updated 6 months ago
- LD_PRELOAD Rootkit☆329Apr 5, 2025Updated last year
- A tool to convert windows registry export files into windows hive files that can be used to replace NTUSER.MAN☆141Jan 26, 2026Updated 5 months ago
- ☆417Dec 8, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Proof-of-Concept tool for extracting credential material from protected sessions on modern Windows systems.☆699May 9, 2026Updated last month
- 「⚔️」Ring 0 Rootkit for Linux Kernels x86/x86_64 5.x/6.x☆27Apr 10, 2025Updated last year
- In-Memory Rootkit For Linux and BSD☆88Aug 9, 2025Updated 10 months ago
- PoC multi-layer protector for ELF32 x86 binaries☆12Feb 26, 2022Updated 4 years ago
- Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)☆152Aug 26, 2024Updated last year
- Because AV evasion should be easy.☆886Nov 28, 2024Updated last year
- Swiss Army Knife for payload encryption, obfuscation, and conversion to byte arrays – all in a single command (14 output formats supporte…☆228Mar 7, 2026Updated 3 months ago
- ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again.☆87Feb 28, 2025Updated last year
- Playing around with Thread Context Hijacking. Building more evasive primitives to use as alternative for existing process injection techn…☆205Jun 17, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connecti…☆453Nov 3, 2025Updated 7 months ago
- InfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution☆157Jun 8, 2026Updated 3 weeks ago
- PowerShell tool that shows how to read and write NTLM OWF values via samlib.dll.☆74Oct 22, 2025Updated 8 months ago
- Windows Kernel Rootkit☆69Nov 24, 2025Updated 7 months ago
- A synergized Visual Studio and Rust development environment☆19Jan 25, 2025Updated last year
- A modern 32/64-bit position independent implant template☆1,350Jun 1, 2026Updated 3 weeks ago
- yet another hidden LKM hunter☆33Sep 18, 2025Updated 9 months ago
- A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.☆626Jan 2, 2025Updated last year
- Ghosting-AMSI☆244Apr 24, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls☆238Aug 31, 2025Updated 10 months ago
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆149Apr 11, 2026Updated 2 months ago
- Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and book…☆559Jan 8, 2026Updated 5 months ago
- SOCKS5 proxy tool that uses Azure Storage services as a means of communication.☆356Mar 21, 2026Updated 3 months ago
- Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods…☆1,670Feb 9, 2026Updated 4 months ago
- PoC to tunnel via AWS Short-Message-Queues☆24Jun 21, 2025Updated last year
- ☆54May 31, 2025Updated last year