MatheuZSecurity / detect-lkm-rootkit-cheatsheetLinks
Cheat sheet to detect and remove linux kernel rootkit
☆74Updated 10 months ago
Alternatives and similar repositories for detect-lkm-rootkit-cheatsheet
Users that are interested in detect-lkm-rootkit-cheatsheet are comparing it to the libraries listed below
Sorting:
- Collection of codes focused on Linux rootkits☆183Updated 3 weeks ago
- Make an Linux Kernel rootkit visible again.☆59Updated 8 months ago
- Lena's scripts/code/resources for malware analysis☆26Updated last year
- ☆71Updated 9 months ago
- ☆37Updated last year
- Vibe Malware Triage - MCP server for static PE analysis.☆72Updated 5 months ago
- Analyse MSI files for vulnerabilities☆138Updated last year
- ☆39Updated 11 months ago
- Modular framework for automating triaging, malware analysis, and analyst workflows☆43Updated 6 months ago
- In-Memory Rootkit For Linux and BSD☆86Updated 3 months ago
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆32Updated 10 months ago
- ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again.☆88Updated 8 months ago
- ☆105Updated last year
- Some of my Malware Analysis writeups☆48Updated last month
- ☆119Updated last year
- A fully-undetectable ransomware that utilizes OneDrive & Google Drive to encrypt target local files☆127Updated last year
- PoC that downloads an executable from a public SSL certificate☆131Updated 3 months ago
- Tools for analyzing EDR agents☆268Updated last year
- A Repository to Track Anti-Forensic Techniques☆114Updated 2 years ago
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆133Updated 3 weeks ago
- Userland exec PoC to be used as attack vector technique☆94Updated 3 weeks ago
- ☆20Updated 2 weeks ago
- NullSection is an Anti-Reversing tool that applies a technique that overwrites the section header with nullbytes.☆68Updated last year
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆130Updated 7 months ago
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆73Updated 2 months ago
- Establishes persistence on a Linux system by creating a udev rule that triggers the execution of a specified payload (binary or script)☆146Updated last year
- ☆114Updated this week
- Hollowise is a tool that implements process hollowing and PPID (Parent Process ID) spoofing techniques for masking a legitimate analysis …☆39Updated 8 months ago
- A library and a set of tools for exploiting and communicating with Google's Quick Share devices.☆47Updated 7 months ago
- ☆132Updated 2 years ago