WeiJiLab / kernel-inline-hook-framework
hook or replace arbitary linux kernel functions in runtime, supporting arm32, arm64, x86, x86_64
☆179Updated last month
Alternatives and similar repositories for kernel-inline-hook-framework:
Users that are interested in kernel-inline-hook-framework are comparing it to the libraries listed below
- linux kernel inline hook☆122Updated 2 years ago
- Trace Android framework API, native libraries, system calls and other events using eBPF☆88Updated 7 months ago
- Change vermagic and CRCs of a Linux Kernel Module☆52Updated 6 years ago
- deobfuse compiler☆214Updated 4 years ago
- Loadable Kernel Module for Android☆71Updated 5 years ago
- A cli tool to install a hardware breakpoint/watchpoint on a process in linux.☆200Updated 7 months ago
- Container and system event tracing using eBPF☆33Updated last month
- A step-by-step tutorial for building an LLVM sample pass☆193Updated 2 years ago
- Code injection on Android without ptrace☆227Updated 11 months ago
- ☆59Updated 5 months ago
- break ollvm.☆99Updated 4 years ago
- A tool that traces system calls using eBPF☆234Updated 4 months ago
- silent syscall hooking without modifying sys_call_table/handlers via patching exception handler☆127Updated 10 months ago
- Shared Library Injector on Android☆146Updated 4 years ago
- ☆34Updated 11 months ago
- IDA plugin, unwind stack trace when debugging arm.☆137Updated 4 years ago
- system call hooking on arm64 linux via a variety of methods☆47Updated 2 years ago
- Android system call hook☆173Updated last month
- btrace:binder_transaction+eBPF+Golang实现通用的Android APP动态行为追踪工具☆157Updated 8 months ago
- a lightweight library to parse Linux's /proc/[pid]/maps file, which contains the memory map of a process☆125Updated 5 months ago
- ☆79Updated 3 years ago
- PLCT实验室维护的ollvm分支。原始代码来自于 https://github.com/obfuscator-llvm/obfuscator 移植到了最新的 LLVM 上。☆167Updated 2 years ago
- Automatically de-obfuscate ollvm and generate binaries☆106Updated 3 years ago
- BTFHub, but for Android☆36Updated last year
- ☆113Updated 2 years ago
- ☆58Updated 7 months ago
- LLVM PASS by SsageParuders.Port to llvm_14.06 with New PM.Support for Android-ndk-r25(LTS).☆159Updated last year
- Syscall table hook frame in Android kernel for arm and arm64☆81Updated 7 years ago
- Unicorn Emulator Debug Server - Written in Rust, with bindings for C, Go, Java and Python☆360Updated last month
- Malicious use of ELF such as .so inject, func hook and so on.☆74Updated 7 years ago