MatheuZSecurity / detect-lkm-rootkit-cheatsheet
Cheat sheet to detect and remove linux kernel rootkit
☆52Updated 3 months ago
Alternatives and similar repositories for detect-lkm-rootkit-cheatsheet:
Users that are interested in detect-lkm-rootkit-cheatsheet are comparing it to the libraries listed below
- Collection of codes focused on Linux rootkits☆92Updated 3 weeks ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆96Updated 11 months ago
- Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content.☆14Updated 2 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆76Updated 6 months ago
- StoneKeeper C2, an experimental EDR evasion framework for research purposes☆194Updated 3 months ago
- ☆18Updated last week
- ☆114Updated last year
- Blocks EDR Telemetry by performing Person-in-the-Middle attack where network filtering is applied using iptables. The blocked destination…☆141Updated 8 months ago
- Windows Persistence IT-Security☆90Updated 2 weeks ago
- ☆35Updated 3 months ago
- Local & remote Windows DLL Proxying☆162Updated 9 months ago
- POC of GITHUB simple C2 in rust☆54Updated last month
- ☆37Updated 11 months ago
- ☆103Updated 4 months ago
- Windows Administrator level Implant.☆49Updated 5 months ago
- Aplos an extremely simple fuzzer for Windows binaries.☆68Updated last month
- Work, timer, and wait callback example using solely Native Windows APIs.☆86Updated last year
- Work in progress experiments with reverse shells, AV bypass and extraction of secrets from memory in C☆39Updated 5 years ago
- CVE-2024-30090 - LPE PoC☆105Updated 5 months ago
- Analyse MSI files for vulnerabilities☆127Updated 6 months ago
- RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging☆160Updated 2 weeks ago
- ☆59Updated last year
- Powershell Linter☆50Updated last week
- ☆75Updated 11 months ago
- Slides for COM Hijacking AV/EDR Talk on 38c3☆72Updated 2 months ago
- lib-nosa is a minimalist C library designed to facilitate socket connections through AFD driver IOCTL operations on Windows.☆106Updated 6 months ago
- A modern 64-bit position independent meterpreter and Sliver compatible reverse_TCP Staging Shellcode based on Cracked5piders Stardust☆84Updated 11 months ago
- This is a simulation of attack by Fancy Bear group (APT28) targeting high-ranking government officials Western Asia and Eastern Europe☆33Updated 9 months ago
- A Mythic Agent written in PIC C.☆184Updated last month
- ☆150Updated 3 months ago