Mrack / MemDetectionLinks
计算内存中的libc.so,libart.so的crc与文件中的对比检测apk是否处于异常环境。
☆76Updated 2 years ago
Alternatives and similar repositories for MemDetection
Users that are interested in MemDetection are comparing it to the libraries listed below
Sorting:
- Frida-Sigaction-Seccomp实现对Android APP系统调用的拦截☆123Updated last year
- 用于练手的环境检测的demo☆88Updated last year
- Android aarch64 kernel rootkit(driver module)☆104Updated 3 weeks ago
- apatch内核模块 用于文件重定向☆71Updated 7 months ago
- android jni trace for arm64 for magisk module!☆85Updated 2 months ago
- frida runtime resolves smali☆89Updated 5 months ago
- Remap a library to avoid detection☆131Updated last year
- 研究内核改机策略☆65Updated last year
- 一个基于ptrace-seccomp简单的重定向openat的demo☆78Updated 2 years ago
- 检测app是否被frida/xposed注入☆60Updated 7 months ago
- 对目标函数进行trace 只适用于 arm64☆108Updated 2 months ago
- 修改app包名,实现随机包名,☆53Updated 3 years ago
- apatch内核模块用于隐藏mountxxx & maps & smaps的指定内容☆62Updated 8 months ago
- Dynamic java method hook for Android,Implemented by jvmti☆58Updated 2 months ago
- This is a tool used to inject so to any app by ptrace.☆91Updated this week
- 一个用于抹去ptrace注入部分文件特征的apatch内核模块☆52Updated 3 weeks ago
- 关于Magisk生态的研究☆154Updated last year
- 一个基于uprobe,能同时hook大量用户地址空间函数的kpm内核模块☆167Updated 3 months ago
- 自實現Linker的小Demo☆73Updated 5 months ago
- ☆63Updated last month
- 个人专用 ONEPLUS 5 内核,做了一些基础的反调试修改(从 maps 隐藏特定 lib,最完整最正常的 tracerPid 修改措施)☆81Updated 4 years ago
- this is Android Custom Linker by Android12 LinkerSourcesCode☆46Updated last year
- fix dex by dump dexCodeItem☆42Updated last year
- A zygisk module that dumps so file from process memory☆90Updated last year
- ☆90Updated 11 months ago
- ☆48Updated 2 years ago
- A zygisk module that hooks `libdexfile.so` to dump dex☆99Updated 11 months ago
- Dynamic java method hook for Android,Implemented by jvmti☆51Updated last year
- Android native SO and DEX dumper.☆48Updated 2 months ago
- frida dump android elf, support spawn and attach mode☆80Updated last year