airbus-cert / dirtypipe-ebpf_detectionLinks
An eBPF detection program for CVE-2022-0847
☆28Updated 3 years ago
Alternatives and similar repositories for dirtypipe-ebpf_detection
Users that are interested in dirtypipe-ebpf_detection are comparing it to the libraries listed below
Sorting:
- ☆89Updated 2 weeks ago
- A collection of projects demonstrating various commandline cloaking techniques on Linux☆59Updated 3 years ago
- Sandfly Linux Stealth Rootkit Decloaking Utility☆107Updated 2 years ago
- insject is a tool for poking at containers. It enables you to run an arbitrary command in a container or any mix of Linux namespaces.☆50Updated 3 years ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆139Updated 2 years ago
- Open Source eBPF Malware Analysis Framework☆53Updated last year
- Linux BPF plugins for Volatility3☆24Updated last year
- Dectect syscall hooking using eBPF☆167Updated 2 years ago
- Example program using eBPF to log data being based in using shell pipes☆41Updated 4 years ago
- This tool have the power to hide any PID/directory in the Linux kernel☆30Updated last year
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆167Updated last year
- egrets monitors egress☆46Updated 5 years ago
- POC for Phantom Attack☆88Updated 3 years ago
- Linux Kernel Runtime Integrity with eBPF☆184Updated 2 years ago
- NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection☆31Updated 2 years ago
- Red Canary's eBPF Sensor☆112Updated 6 months ago
- io_uring based network scanner written in Rust☆45Updated last month
- bdvl☆115Updated 3 years ago
- ☆31Updated 4 years ago
- Linux Kernel module-less implant (backdoor)☆74Updated 4 years ago
- Paracosme is a zero-click remote memory corruption exploit that compromises ICONICS Genesis64 which was demonstrated successfully on stag…☆89Updated 2 years ago
- Project containing several tools/ scripts to recover the OpenSSH session keys used to encrypt/ decrypt SSH traffic.☆93Updated last year
- A pcap capture analysis helper☆25Updated 2 years ago
- YARI is an interactive debugger for YARA Language.☆90Updated 3 months ago
- Mara is a userland pty/tty sniffer☆53Updated 2 years ago
- A collection of bypasses and exploits for eBPF-based cloud security.☆25Updated last year
- Rust Linux Kernel Module designed for LKM rootkit detection☆56Updated 9 months ago
- ☆48Updated 5 years ago
- Execute MachO binaries in memory using CGo☆79Updated 4 years ago
- ☆64Updated last year