A rootkit for Android.
☆63Jun 6, 2024Updated last year
Alternatives and similar repositories for kmem
Users that are interested in kmem are comparing it to the libraries listed below
Sorting:
- A kernel module to read and write memory in a remote process.☆75Aug 27, 2024Updated last year
- 劫持Zygote在App启动前注入so☆347Jan 22, 2026Updated last month
- 去除BR混淆 Deobfuscation BR☆91Jun 20, 2024Updated last year
- Draw on Canvas based Overlay with RootService☆19Apr 13, 2024Updated last year
- tprt ollvm 反混淆 修改 binja il☆50Sep 5, 2024Updated last year
- Xposed免root注入so方案, 支持android各个版本☆242May 1, 2024Updated last year
- Mirror of https://gitee.com/SmartSmallBoy/hardware-breakpoint☆60May 20, 2024Updated last year
- Android system call hook☆228Jan 22, 2025Updated last year
- apatch kpm 模块通用内核读写内存 linux kernel read only support ARM64(based apatch)☆66Jan 13, 2026Updated last month
- AntiOllvm Fla with Fake Runtime☆182Jan 8, 2025Updated last year
- btrace:binder_transaction+eBPF+Golang实现通用的Android APP动态行为追踪工具☆199Jun 15, 2024Updated last year
- 自實現Linker的小Demo☆76Jun 5, 2025Updated 8 months ago
- Android aarch64 kernel driver module providing efficient memory operations, touch simulation and IPC. Features include fast memory remapp…☆98Aug 25, 2025Updated 6 months ago
- 研究内核改机策略☆69Mar 13, 2024Updated last year
- ☆105Dec 5, 2024Updated last year
- ☆34Dec 30, 2024Updated last year
- 详细说明及演示MMU相关原理及过程(用于理解Linux内核Root Kernelpatch)☆23Jun 17, 2024Updated last year
- Android Kernel Vulnerability (CVE-2019-2215) temporary root PoC☆14Dec 21, 2023Updated 2 years ago
- A library for hiding and retrieving imports in ELF binaries.☆192Apr 18, 2025Updated 10 months ago
- Android aarch64 kernel rootkit(driver module)☆136Dec 10, 2025Updated 2 months ago
- ☆147Sep 9, 2025Updated 5 months ago
- 一个基于uprobe,能同时hook大量用户地址空间函数的kpm内核模块☆186Feb 13, 2026Updated 2 weeks ago
- A demo app to detect Zygote injections☆111Jan 29, 2026Updated last month
- ☆94Feb 11, 2026Updated 2 weeks ago
- Android native SO and DEX dumper.☆70Aug 22, 2025Updated 6 months ago
- Single-step debugging of native code using frida, stalker, and semaphore☆87Oct 9, 2024Updated last year
- silent syscall hooking without modifying sys_call_table/handlers via patching exception handler☆152Apr 22, 2024Updated last year
- ☆93Mar 4, 2025Updated 11 months ago
- ☆175Jun 27, 2025Updated 8 months ago
- 个人专用 ONEPLUS 5 内核,做了一些基础的反调试修改(从 maps 隐藏特定 lib,最完整最正常的 tracerPid 修改措施)☆81Oct 7, 2021Updated 4 years ago
- android8 arm64 注入方案☆37Jul 11, 2021Updated 4 years ago
- 本工具用于在无Linux内核源码的情况下,查找出内核函数load_module的位置,确保在无内核源码的情况下,顺利去除所有加载驱动的验证,此工具适用于所有Linux ARM64内核☆131Jul 30, 2025Updated 7 months ago
- Linux ARM64内核硬件进程内存读写驱动、硬件断点调试驱动。硬件级读写Linux进程内存、硬件级下断点。☆892Dec 4, 2025Updated 2 months ago
- A cli tool to install a hardware breakpoint/watchpoint on a process in linux.☆246Jul 6, 2024Updated last year
- 计算内存中的libc.so,libart.so的crc与文件中的对比检测apk是否处于异常环境。☆82Dec 13, 2022Updated 3 years ago
- Modify Android linker to provide loading module and hook function☆463Oct 13, 2025Updated 4 months ago
- Use frida-gum's stalker for tracing☆81Jan 10, 2026Updated last month
- dump dex for android 14☆66Oct 4, 2024Updated last year
- fla反混淆☆58Jul 29, 2025Updated 7 months ago