A curated compilation of extensive resources dedicated to bootkit and rootkit development.
☆263Aug 16, 2026Updated last week
Alternatives and similar repositories for Awesome-Bootkits-Rootkits-Development
Users that are interested in Awesome-Bootkits-Rootkits-Development are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Automated environment setup for Bootkit & Rootkit development.☆45Aug 16, 2026Updated last week
- Windows Kernel Rootkit☆76Aug 16, 2026Updated last week
- Starter pack for learning how to develop UEFI bootkits: basic proof-of-concepts, development environment configuration, and step-by-step …☆30Jul 31, 2026Updated 3 weeks ago
- Starter pack for learning how to develop Kernel-Mode rootkits: basic proof-of-concepts, development environment configuration, and step-b…☆24Jul 31, 2026Updated 3 weeks ago
- The first publicly shared complete Windows UEFI bootkit framework for automated Ring0 rootkit deployment and APT emulation☆164Aug 16, 2026Updated last week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- [ARCHIVED] Early work on Benthic (Windows Kernel Rootkit).☆59Aug 15, 2025Updated last year
- Use PKfail to install UEFI Bootkits☆23Aug 16, 2026Updated last week
- [ARCHIVED] Early work on Abyss (Windows UEFI Bootkit).☆43Aug 15, 2025Updated last year
- PIC shellcode (C/C++) development toolkit designed for malware developers.☆133Dec 23, 2025Updated 8 months ago
- A talk about finding your own path to vulnerability research and your first CVE.☆16Apr 4, 2026Updated 4 months ago
- Dynamic shellcode loader with sophisticated evasion capabilities☆346Oct 1, 2025Updated 10 months ago
- A Cobalt Strike payload generator and lateral movement aggressor script which places Beacon shellcode into a custom shellcode loader☆46Sep 25, 2024Updated last year
- Windows rootkit designed to work with BYOVD exploits☆224Jan 18, 2025Updated last year
- Automatically scan the file system to identify Electron applications vulnerable to ASAR tampering.☆164Nov 28, 2025Updated 8 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A Swiss Army knife for offensive security with its own blades.☆16May 18, 2025Updated last year
- Stealthy Linux Kernel Rootkit for modern kernels (6x)☆1,734Jun 11, 2026Updated 2 months ago
- Dump protected process memory by using BYOVD to tamper with handle objects in the kernel.☆46Aug 5, 2025Updated last year
- Indirect Syscall invocation via thread hijacking☆27May 5, 2023Updated 3 years ago
- A header-only, freestanding C++20 template for IR-bytecode VM loaders☆27May 10, 2026Updated 3 months ago
- Minimalistic HTTP(S) client for the NT kernel☆61Dec 1, 2025Updated 8 months ago
- Another UEFI runtime bootkit☆36May 8, 2023Updated 3 years ago
- AV/EDR Lab environment setup references to help in Malware development☆469Feb 19, 2025Updated last year
- Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR …☆313Jul 31, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- SMM driver/rootkit for platform memory access with R3 <-> R0 <-> R-2 communication.☆121Oct 15, 2024Updated last year
- Playing around with Thread Context Hijacking. Building more evasive primitives to use as alternative for existing process injection techn…☆207Jun 17, 2025Updated last year
- stack based arithmetic only virtual machine (VM) executes bytecode instructions to perform various basic arithmetic operations and manage…☆27Mar 19, 2025Updated last year
- Windows 11 24H2-25H2 Runtime PatchGuard Bypass☆265Nov 4, 2025Updated 9 months ago
- Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.☆640Feb 2, 2026Updated 6 months ago
- Demonstrate calling a kernel function and handle process creation callback against HVCI☆85Dec 21, 2022Updated 3 years ago
- Havoc 3rd party agent. Designed to be evasive. Fully PIC shellcode agent.☆17Dec 29, 2022Updated 3 years ago
- Bring your own Unwind Data Framework☆169Mar 15, 2026Updated 5 months ago
- A self-hosted sandbox for red teams to test payloads against modern detection before deployment. MCP integration lets an LLM agent drive …☆1,522May 5, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- BSides Prishtina 2024 Malware Development and Persistence workshop☆151Jun 11, 2026Updated 2 months ago
- Open Source Implementation of Cobalt Strike's Malleable C2☆107Jun 27, 2026Updated last month
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆132Aug 19, 2025Updated last year
- BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE…☆913Updated this week
- PICO-Implant is a Proof of Concept C2 implant built using Position-independent Code Objects (PICO) for modular functionality. This projec…☆57Nov 9, 2025Updated 9 months ago
- Now You See Me, Now You Don't☆1,061May 22, 2026Updated 3 months ago
- Shared object ELF Process injection and loading resources.☆12May 9, 2026Updated 3 months ago