A curated compilation of extensive resources dedicated to bootkit and rootkit development.
☆273Aug 16, 2026Updated 3 weeks ago
Alternatives and similar repositories for Awesome-Bootkits-Rootkits-Development
Users that are interested in Awesome-Bootkits-Rootkits-Development are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automated environment setup for Bootkit & Rootkit development.☆45Aug 16, 2026Updated 3 weeks ago
- Windows Kernel Rootkit☆80Aug 16, 2026Updated 3 weeks ago
- Starter pack for learning how to develop UEFI bootkits: basic proof-of-concepts, development environment configuration, and step-by-step …☆34Jul 31, 2026Updated last month
- Starter pack for learning how to develop Kernel-Mode rootkits: basic proof-of-concepts, development environment configuration, and step-b…☆27Jul 31, 2026Updated last month
- The first publicly shared complete Windows UEFI bootkit framework for automated Ring0 rootkit deployment and APT emulation☆165Aug 16, 2026Updated 3 weeks ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- [ARCHIVED] Early work on Benthic (Windows Kernel Rootkit).☆59Aug 15, 2025Updated last year
- Use PKfail to install UEFI Bootkits☆24Aug 16, 2026Updated 3 weeks ago
- [ARCHIVED] Early work on Abyss (Windows UEFI Bootkit).☆43Aug 15, 2025Updated last year
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆134Dec 23, 2025Updated 8 months ago
- A talk about finding your own path to vulnerability research and your first CVE.☆16Apr 4, 2026Updated 5 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆345Oct 1, 2025Updated 11 months ago
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆46Sep 25, 2024Updated last year
- Windows rootkit designed to work with BYOVD exploits☆226Jan 18, 2025Updated last year
- Automatically scan the file system to identify Electron applications vulnerable to ASAR tampering.☆163Nov 28, 2025Updated 9 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A Swiss Army knife for offensive security with its own blades.☆16May 18, 2025Updated last year
- ☆21Dec 4, 2025Updated 9 months ago
- Stealthy Linux Kernel Rootkit for modern kernels (6x)☆1,756Sep 5, 2026Updated last week
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆47Aug 5, 2025Updated last year
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 4 months ago
- Minimalistic HTTP(S) client for the NT kernel☆61Dec 1, 2025Updated 9 months ago
- Indirect Syscall invocation via thread hijacking☆27May 5, 2023Updated 3 years ago
- Another UEFI runtime bootkit☆35May 8, 2023Updated 3 years ago
- AV/EDR Lab environment setup references to help in Malware development☆471Feb 19, 2025Updated last year
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆314Jul 31, 2024Updated 2 years ago
- Playing around with Thread Context Hijacking. Building more evasive primitives to use as alternative for existing process injection techn…☆210Jun 17, 2025Updated last year
- SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.☆126Oct 15, 2024Updated last year
- Windows 11 24H2-25H2 Runtime PatchGuard Bypass☆267Nov 4, 2025Updated 10 months ago
- stack based arithmetic only virtual machine (VM) executes bytecode instructions to perform various basic arithmetic operations and manage…☆27Mar 19, 2025Updated last year
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆646Feb 2, 2026Updated 7 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆87Dec 21, 2022Updated 3 years ago
- Havoc 3rd party agent. Designed to be evasive. Fully PIC shellcode agent.☆17Dec 29, 2022Updated 3 years ago
- Bring your own Unwind Data Framework☆172Mar 15, 2026Updated 5 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,537May 5, 2026Updated 4 months ago
- BSides Prishtina 2024 Malware Development and Persistence workshop☆150Jun 11, 2026Updated 3 months ago
- Open Source Implementation of Cobalt Strike's Malleable C2☆108Jun 27, 2026Updated 2 months ago
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆133Aug 19, 2025Updated last year
- PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This projec…☆57Nov 9, 2025Updated 10 months ago
- BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE…☆940Aug 18, 2026Updated 3 weeks ago
- string/file/shellcode encryptor using AES/XOR☆11Oct 15, 2023Updated 2 years ago