A curated compilation of extensive resources dedicated to bootkit and rootkit development.
☆282Aug 16, 2026Updated last month
Alternatives and similar repositories for Awesome-Bootkits-Rootkits-Development
Users that are interested in Awesome-Bootkits-Rootkits-Development are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automated environment setup for Bootkit & Rootkit development.☆46Aug 16, 2026Updated last month
- Windows Kernel Rootkit☆81Aug 16, 2026Updated last month
- Starter pack for learning how to develop UEFI bootkits: basic proof-of-concepts, development environment configuration, and step-by-step …☆38Jul 31, 2026Updated 2 months ago
- Starter pack for learning how to develop Kernel-Mode rootkits: basic proof-of-concepts, development environment configuration, and step-b…☆28Jul 31, 2026Updated 2 months ago
- The first publicly shared complete Windows UEFI bootkit framework for automated Ring0 rootkit deployment and APT emulation☆166Aug 16, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- [ARCHIVED] Early work on Benthic (Windows Kernel Rootkit).☆58Aug 15, 2025Updated last year
- Use PKfail to install UEFI Bootkits☆24Aug 16, 2026Updated last month
- [ARCHIVED] Early work on Abyss (Windows UEFI Bootkit).☆42Aug 15, 2025Updated last year
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆135Dec 23, 2025Updated 9 months ago
- A talk about finding your own path to vulnerability research and your first CVE.☆16Apr 4, 2026Updated 5 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆346Oct 1, 2025Updated last year
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆44Sep 25, 2024Updated 2 years ago
- Windows rootkit designed to work with BYOVD exploits☆225Jan 18, 2025Updated last year
- Automatically scan the file system to identify Electron applications vulnerable to ASAR tampering.☆162Nov 28, 2025Updated 10 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A Swiss Army knife for offensive security with its own blades.☆18May 18, 2025Updated last year
- Stealthy Linux Kernel Rootkit☆1,779Sep 21, 2026Updated last week
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆47Aug 5, 2025Updated last year
- Minimalistic HTTP(S) client for the NT kernel☆60Dec 1, 2025Updated 10 months ago
- Indirect Syscall invocation via thread hijacking☆27May 5, 2023Updated 3 years ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆26May 10, 2026Updated 4 months ago
- Another UEFI runtime bootkit☆35May 8, 2023Updated 3 years ago
- AV/EDR Lab environment setup references to help in Malware development☆471Feb 19, 2025Updated last year
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆311Jul 31, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Playing around with Thread Context Hijacking. Building more evasive primitives to use as alternative for existing process injection techn…☆209Jun 17, 2025Updated last year
- SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.☆128Oct 15, 2024Updated last year
- Windows 11 24H2-25H2 Runtime PatchGuard Bypass☆270Nov 4, 2025Updated 10 months ago
- stack based arithmetic only virtual machine (VM) executes bytecode instructions to perform various basic arithmetic operations and manage…☆27Mar 19, 2025Updated last year
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆652Feb 2, 2026Updated 8 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆86Dec 21, 2022Updated 3 years ago
- Havoc 3rd party agent. Designed to be evasive. Fully PIC shellcode agent.☆17Dec 29, 2022Updated 3 years ago
- Bring your own Unwind Data Framework☆176Mar 15, 2026Updated 6 months ago
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,543May 5, 2026Updated 4 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- BSides Prishtina 2024 Malware Development and Persistence workshop☆153Jun 11, 2026Updated 3 months ago
- Open Source Implementation of Cobalt Strike's Malleable C2☆108Jun 27, 2026Updated 3 months ago
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆133Aug 19, 2025Updated last year
- PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This projec…☆56Nov 9, 2025Updated 10 months ago
- BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE…☆962Aug 18, 2026Updated last month
- string/file/shellcode encryptor using AES/XOR☆11Oct 15, 2023Updated 2 years ago
- Now You See Me, Now You Don't☆1,069May 22, 2026Updated 4 months ago