MatheuZSecurity / detect-lkm-rootkit-cheatsheet
Cheat sheet to detect and remove linux kernel rootkit
☆55Updated 4 months ago
Alternatives and similar repositories for detect-lkm-rootkit-cheatsheet:
Users that are interested in detect-lkm-rootkit-cheatsheet are comparing it to the libraries listed below
- ☆36Updated 4 months ago
- Aplos an extremely simple fuzzer for Windows binaries.☆68Updated 2 months ago
- Lena's scripts/code/resources for malware analysis☆26Updated 10 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆98Updated last year
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆109Updated 7 months ago
- ☆104Updated 5 months ago
- Slides for COM Hijacking AV/EDR Talk on 38c3☆73Updated 3 months ago
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆15Updated 3 months ago
- Collection of codes focused on Linux rootkits☆105Updated last month
- ☆18Updated last month
- Malware Analysis tools☆26Updated 7 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆78Updated 7 months ago
- Make an Linux Kernel rootkit visible again.☆50Updated last month
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆36Updated last month
- Powershell Linter☆50Updated 2 weeks ago
- IDA Python scripts☆34Updated last week
- Local & remote Windows DLL Proxying☆164Updated 10 months ago
- POC of GITHUB simple C2 in rust☆53Updated 2 months ago
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆40Updated 2 weeks ago
- Version 2 - A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders …☆102Updated 3 weeks ago
- ☆38Updated 2 years ago
- ☆66Updated 2 months ago
- ☆154Updated 4 months ago
- A proof-of-concept C2 channel through DuckDuckGo's image proxy service☆74Updated last year
- Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers☆117Updated 7 months ago
- Situational Awareness script to identify how and where to run implants☆50Updated 4 months ago
- NidhoggScript is a tool to generate "script" file that allows execution of multiple commands for Nidhogg☆46Updated last year
- ☆23Updated 2 months ago
- ☆37Updated last year
- ☆105Updated 9 months ago