airbus-cert / dirtypipe-ebpf_detectionLinks
An eBPF detection program for CVE-2022-0847
☆28Updated 3 years ago
Alternatives and similar repositories for dirtypipe-ebpf_detection
Users that are interested in dirtypipe-ebpf_detection are comparing it to the libraries listed below
Sorting:
- A collection of projects demonstrating various commandline cloaking techniques on Linux☆59Updated 3 years ago
- ☆90Updated last month
- Sandfly Linux Stealth Rootkit Decloaking Utility☆108Updated 3 years ago
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆168Updated last year
- Open Source eBPF Malware Analysis Framework☆54Updated last year
- POC for Phantom Attack☆89Updated 3 years ago
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.☆50Updated 4 years ago
- Paracosme is a zero-click remote memory corruption exploit that compromises ICONICS Genesis64 which was demonstrated successfully on stag…☆89Updated 2 years ago
- Dectect syscall hooking using eBPF☆168Updated 2 years ago
- Linux Kernel Runtime Integrity with eBPF☆184Updated 2 years ago
- Execute MachO binaries in memory using CGo☆79Updated 4 years ago
- Mara is a userland pty/tty sniffer☆53Updated 2 years ago
- Cisco ASA Software and ASDM Security Research☆86Updated 3 years ago
- Electron-Probe leverages the Node variant of the Chrome Debugging Protocol to execute JavaScript payloads inside of target Electron appli…☆31Updated 3 weeks ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆139Updated 2 years ago
- Red Canary's eBPF Sensor☆113Updated 7 months ago
- A simple tool to create mermaid js markdown charts from CVE IDs and CVE keyword searches.☆47Updated 3 years ago
- Userland exec PoC to be used as attack vector technique☆94Updated 3 months ago
- WallEscape vulnerability in util-linux☆51Updated last year
- Linux based vulnerabilities (CVE) exploit detection through runtime security using Falco/Osquery/Yara/Sigma☆21Updated 2 years ago
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆136Updated 8 months ago
- Linux Kernel module-less implant (backdoor)☆73Updated 4 years ago
- Ghidra scripts for recovering string definitions in Go binaries☆127Updated 2 months ago
- A collection of bypasses and exploits for eBPF-based cloud security.☆25Updated 2 years ago
- Unsafe Unpacking Vulnerability: Lab Code, Semgrep Rules and Secure Implementation Guide☆42Updated last year
- Presentations from the CX Security Labs team☆35Updated 6 months ago
- Invanti VPN Vulnerabilities for Jan - Feb 2024 - Links to Keep it all Organized☆16Updated last year
- This tool have the power to hide any PID/directory in the Linux kernel☆30Updated last year
- Finds imports that could be exploited, still requires manual analysis.☆29Updated 3 years ago
- Determine whether your compute is truly vulnerable to a specific vulnerability by accounting for all factors which affect *actual* exploi…☆141Updated 2 years ago