io_uring based rootkit
☆263Apr 24, 2025Updated last year
Alternatives and similar repositories for curing
Users that are interested in curing are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆133Apr 13, 2025Updated last year
- Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.☆383Aug 29, 2025Updated 11 months ago
- Pack/Encrypt/Obfuscate ELF + SHELL scripts☆455Apr 11, 2026Updated 3 months ago
- Stealthy Linux Kernel Rootkit for modern kernels (6x)☆1,725Jun 11, 2026Updated last month
- Fast and easy to use CLI-based file encryption program 📦☆13Oct 12, 2025Updated 9 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Locate dlls and function addresses without PEB Walk and EAT parsing☆110Nov 7, 2025Updated 9 months ago
- A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Cal…☆266Jun 10, 2025Updated last year
- Collection of codes focused on Linux rootkits☆220Oct 22, 2025Updated 9 months ago
- In-Memory Rootkit For Linux and BSD☆88Aug 9, 2025Updated last year
- Red-Team LKM☆653May 31, 2026Updated 2 months ago
- Code execution/injection technique using DLL PEB module structure manipulation☆289Jun 4, 2025Updated last year
- Rust implementation, creating a scheduled task programmatically with user logon trigger.☆47Jun 10, 2025Updated last year
- A penetration toolkit for container environment☆153Updated this week
- Utilizng an MCP Server to communicate with your C2☆95May 15, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- find dll base addresses without PEB WALK☆170Jul 13, 2025Updated last year
- Elf binary infector written in Go.☆216Jan 11, 2025Updated last year
- A Rust version of Mirage, a PoC memory evasion technique that relies on a vulnerable VBS enclave to hide shellcode within VTL1.☆40Mar 6, 2025Updated last year
- Rust Linux Kernel Module designed for LKM rootkit detection☆63Mar 12, 2025Updated last year
- ☆87Mar 30, 2026Updated 4 months ago
- Listener that spawns a new tmux window for each incoming reverse shell + Supports listening on many ports☆59Jul 13, 2025Updated last year
- 🔍 Function-level tracing tool for Seccomp profiling, with eBPF☆177Feb 23, 2026Updated 5 months ago
- Exploit for CVE-2025-21756 for Linux kernel 6.6.75. My first linux kernel exploit!☆162Jun 5, 2025Updated last year
- Kubescape eBPF agent 🥷🏻☆37Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- The dragon in the dark. A red team post exploitation framework for testing security controls during red team assessments.☆512Mar 15, 2026Updated 4 months ago
- A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs☆340Feb 27, 2026Updated 5 months ago
- Linux kernel integrity monitor for detecting syscall hooking☆88Feb 16, 2026Updated 5 months ago
- Nameless C2 - A C2 with all its components written in Rust☆282Sep 26, 2024Updated last year
- Sleep Obfuscation in Rust☆286Dec 1, 2025Updated 8 months ago
- A Windows rootkit that turns user-land processes into Protected Processes☆30Nov 16, 2024Updated last year
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆696Jul 7, 2024Updated 2 years ago
- eBPF Memory Dump Tool☆113May 7, 2026Updated 3 months ago
- Noradrenaline is a collection of high-performance post-exploitation shared libraries designed for native execution on macOS and Linux end…☆30Jul 6, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- This technique leverages PowerShell's .NET interop layer and COM automation to achieve stealthy command execution by abusing implicit typ…☆54May 16, 2025Updated last year
- A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malwar…☆136Sep 19, 2021Updated 4 years ago
- A command and control framework written in rust.☆392Aug 4, 2026Updated last week
- Rust implementation of phantom persistence technique documented in https://blog.phantomsec.tools/phantom-persistence☆65Jun 23, 2025Updated last year
- Nakamoto is a 2 layer encryption tool to protect your data and your cyptocurrency☆16Aug 2, 2026Updated last week
- Windows hypervisor for Intel x64: defensive host hypervisor for Windows designed to mitigate kernel-level attacks including BYOVD, compat…☆270Jul 18, 2026Updated 3 weeks ago
- A windows 11 rootkit in Rust☆19Mar 23, 2025Updated last year