armosec / curingLinks
io_uring based rootkit
☆243Updated 6 months ago
Alternatives and similar repositories for curing
Users that are interested in curing are comparing it to the libraries listed below
Sorting:
- eBPF hacks☆187Updated 11 months ago
- A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs☆331Updated 4 months ago
- eBPF Memory Dump Tool☆90Updated 2 months ago
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆135Updated 5 months ago
- A library for intercepting system calls☆104Updated 10 months ago
- Rust Linux Kernel Module designed for LKM rootkit detection☆53Updated 8 months ago
- Userland exec PoC to be used as attack vector technique☆94Updated 3 weeks ago
- ☆135Updated last year
- An eBPF🐝 Keylogger with C2-based RCE payload delivery☆299Updated 6 months ago
- nysm is a stealth post-exploitation container.☆265Updated 5 months ago
- An eBPF playground☆209Updated last year
- Make your programs stealthier🐝☆194Updated 5 months ago
- Utility to find hidden Linux kernel modules☆146Updated 3 months ago
- This tool have the power to hide any PID/directory in the Linux kernel☆30Updated last year
- Open Source eBPF Malware Analysis Framework☆53Updated last year
- Zaps arguments and environment from the process list☆235Updated last year
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆167Updated last year
- WallEscape vulnerability in util-linux☆52Updated last year
- An ssh honeypot with the XZ backdoor. CVE-2024-3094☆144Updated last year
- Deep Linux runtime visibility meets Wireshark☆295Updated last week
- A collection of bypasses and exploits for eBPF-based cloud security.☆25Updated last year
- Tooling backed by an LLM for performing natural language searches against compiled target binaries. Search for encryption code, password …☆163Updated last year
- Linpmem is a linux memory acquisition tool☆94Updated 4 months ago
- Heavily-modified fork of David Buchanan's dlinject project. Injects arbitrary assembly (or precompiled binary) payloads directly into x86…☆142Updated 3 years ago
- Python tool to resolve all strings in Go binaries obfuscated by garble☆134Updated 8 months ago
- Fingerprint-aware TLS reverse proxy. Use Finch to outsmart bad traffic—collect client fingerprints (JA3, JA4 +QUIC, JA4H, HTTP/2) and act…☆249Updated 2 weeks ago
- ☆89Updated last year
- ☆85Updated 3 weeks ago
- ulexecve is a userland execve() implementation which helps you execute arbitrary ELF binaries on Linux from userland without the binaries…☆196Updated last year
- Self-contained script for cleaning forensic traces on Linux, macOS, and Windows.☆114Updated 3 months ago