A curated compilation of extensive resources dedicated to bootkit and rootkit development.
☆247Jul 31, 2026Updated this week
Alternatives and similar repositories for Awesome-Bootkits-Rootkits-Development
Users that are interested in Awesome-Bootkits-Rootkits-Development are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automated environment setup for Bootkit & Rootkit development.☆42Jul 10, 2026Updated 3 weeks ago
- Windows Kernel Rootkit☆74Nov 24, 2025Updated 8 months ago
- Starter pack for learning how to develop UEFI bootkits: basic proof-of-concepts, development environment configuration, and step-by-step …☆26Updated this week
- Starter pack for learning how to develop Kernel-Mode rootkits: basic proof-of-concepts, development environment configuration, and step-b…☆22Updated this week
- The first publicly shared complete Windows UEFI bootkit framework for automated Ring0 rootkit deployment and APT emulation☆160Nov 24, 2025Updated 8 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- [ARCHIVED] Early work on Benthic (Windows Kernel Rootkit).☆58Aug 15, 2025Updated 11 months ago
- Use PKfail to install UEFI Bootkits☆22Jul 8, 2025Updated last year
- [ARCHIVED] Early work on Abyss (Windows UEFI Bootkit).☆42Aug 15, 2025Updated 11 months ago
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆132Dec 23, 2025Updated 7 months ago
- A talk about finding your own path to vulnerability research and your first CVE.☆16Apr 4, 2026Updated 3 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆346Oct 1, 2025Updated 10 months ago
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆46Sep 25, 2024Updated last year
- Windows rootkit designed to work with BYOVD exploits☆225Jan 18, 2025Updated last year
- Automatically scan the file system to identify Electron applications vulnerable to ASAR tampering.☆162Nov 28, 2025Updated 8 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A Swiss Army knife for offensive security with its own blades.☆16May 18, 2025Updated last year
- Stealthy Linux Kernel Rootkit for modern kernels (6x)☆1,723Jun 11, 2026Updated last month
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆42Aug 5, 2025Updated 11 months ago
- Indirect Syscall invocation via thread hijacking☆27May 5, 2023Updated 3 years ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 2 months ago
- Minimalistic HTTP(S) client for the NT kernel☆61Dec 1, 2025Updated 8 months ago
- Another UEFI runtime bootkit☆35May 8, 2023Updated 3 years ago
- AV/EDR Lab environment setup references to help in Malware development☆469Feb 19, 2025Updated last year
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆312Jul 31, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Playing around with Thread Context Hijacking. Building more evasive primitives to use as alternative for existing process injection techn…☆207Jun 17, 2025Updated last year
- SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.☆122Oct 15, 2024Updated last year
- Windows 11 24H2-25H2 Runtime PatchGuard Bypass☆266Nov 4, 2025Updated 9 months ago
- stack based arithmetic only virtual machine (VM) executes bytecode instructions to perform various basic arithmetic operations and manage…☆27Mar 19, 2025Updated last year
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆642Feb 2, 2026Updated 6 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆85Dec 21, 2022Updated 3 years ago
- Havoc 3rd party agent. Designed to be evasive. Fully PIC shellcode agent.☆17Dec 29, 2022Updated 3 years ago
- Bring your own Unwind Data Framework☆163Mar 15, 2026Updated 4 months ago
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,507May 5, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- BSides Prishtina 2024 Malware Development and Persistence workshop☆147Jun 11, 2026Updated last month
- Open Source Implementation of Cobalt Strike's Malleable C2☆106Jun 27, 2026Updated last month
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆131Aug 19, 2025Updated 11 months ago
- BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE…☆881Jul 12, 2026Updated 3 weeks ago
- PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This projec…☆57Nov 9, 2025Updated 8 months ago
- string/file/shellcode encryptor using AES/XOR☆11Oct 15, 2023Updated 2 years ago
- Now You See Me, Now You Don't☆1,061May 22, 2026Updated 2 months ago