Linux kernel integrity monitor for detecting syscall hooking
☆88Feb 16, 2026Updated 5 months ago
Alternatives and similar repositories for ksentinel
Users that are interested in ksentinel are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Swiss Army knife for offensive security with its own blades.☆16May 18, 2025Updated last year
- Collection of codes focused on Linux rootkits☆220Oct 22, 2025Updated 9 months ago
- Intel 64/Windows low-level experiments☆108Jul 21, 2026Updated 2 weeks ago
- ☆22Mar 22, 2025Updated last year
- Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.☆383Aug 29, 2025Updated 11 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- 「⚔️」Ring 0 Rootkit for Linux Kernels x86/x86_64 5.x/6.x☆27Apr 10, 2025Updated last year
- Implementation of KlezVirus' silent moonwalk approach for payloads☆18Feb 13, 2026Updated 5 months ago
- Stealthy Linux Kernel Rootkit for modern kernels (6x)☆1,725Jun 11, 2026Updated last month
- Attacking the cleanup_module function of a kernel module☆57Jun 30, 2025Updated last year
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆133Apr 13, 2025Updated last year
- Cosmic Rowhammer - Crowdsourcing random bitflips for exploitation☆25Mar 18, 2026Updated 4 months ago
- Post-exploitation and evasion research toolkit for Linux.☆259Jul 22, 2026Updated 2 weeks ago
- Harness to issue Virtual Secure Mode (VSM) "secure calls" from VTL 0 to VTL 1☆81Sep 8, 2025Updated 11 months ago
- ☆48Dec 21, 2025Updated 7 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- An analysis of intels goldmont plus uarch predecode caches core logic due to it being undocumented☆18Jul 12, 2025Updated last year
- A Linux kernel integrity scanner☆17May 2, 2026Updated 3 months ago
- A ring0 Loadable Kernel Module (Linux) for latest kernels 6.x☆105Dec 16, 2025Updated 7 months ago
- Author of Project Adrishya a rootkit which use ftrace mechanism to hook syscall; (write this because God commanded me); work for both x86…☆32Sep 19, 2025Updated 10 months ago
- Kassandra is a custom Mythic C2 agent written in Rust, containerized via a Python-based builder☆18Jul 31, 2026Updated last week
- Make an Linux Kernel rootkit visible again.☆58Feb 27, 2025Updated last year
- ☆28Jun 21, 2026Updated last month
- Linux Rootkit (x86-64 / ARM64) that stealth hides processes, files, and sockets, hooks syscalls, encrypts traffic, and bypasses SELinux /…☆29Aug 24, 2025Updated 11 months ago
- Extensible MacOS system telemetry generator.☆62Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Manage Shadows Copies via the VSS API using C#, C++, Crystal or Python. Working on Windows 11☆84Jan 26, 2026Updated 6 months ago
- An IDA plugin that uses language models to speed up binary analysis.☆51Nov 23, 2025Updated 8 months ago
- LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footpr…☆19May 25, 2026Updated 2 months ago
- A Python script to authenticate and test access to Google Cloud Platform (GCP) resources.☆19Jan 31, 2024Updated 2 years ago
- SPiCa (System Process Integrity & Cross-view Analysis) is a high-performance, eBPF-based rootkit detection engine written in Rust, inspir…☆104Jul 14, 2026Updated 3 weeks ago
- This is a collection of Worms for educational purposes☆36Jul 17, 2025Updated last year
- Windows 11 kernel research framework demonstrating DSE bypass on Windows 11 25H2 through boot-time execution. Loads unsigned drivers by s…☆251Apr 9, 2026Updated 4 months ago
- A protracted people's rootkit.☆19May 1, 2026Updated 3 months ago
- Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps…☆39Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Cheat sheet to detect and remove linux kernel rootkit☆81Dec 16, 2024Updated last year
- 🛡️Proactive ransomware defense for Windows, providing secure file hiding through camouflage, encrypted mappings, smart shortcuts and sea…☆16Oct 14, 2025Updated 9 months ago
- An modular asset discovery framework written in python to automate the repeating manual work☆84Updated this week
- A Volatility plugin to detect hidden Linux Kernel Modules☆16Jul 11, 2025Updated last year
- PoC showing how a potentially malicious script could be hidden, encrypted, into invisible unicode characters☆15May 26, 2019Updated 7 years ago
- PoC to tunnel via AWS Short-Message-Queues☆24Jun 21, 2025Updated last year
- Emulation of Binary Ninja LLIL☆17Feb 24, 2026Updated 5 months ago