bluedragonsecurity / bds_lkm_ftrace
Ftrace Based Linux Loadable Kernel Module Rootkit for Linux Kernel 5.x and 6.x on x86_64, hides files, hides process, hides bind shell & reverse shell port, privilege escalation, cleans up logs and bash history during installation
☆16Updated last year
Alternatives and similar repositories for bds_lkm_ftrace:
Users that are interested in bds_lkm_ftrace are comparing it to the libraries listed below
- Code injection from Linux kernel to a process☆19Updated last year
- BPFDoor Source Code. Originally found from Chinese Threat Actor Red Menshen☆43Updated 2 years ago
- Report and exploit of CVE-2023-36427☆89Updated last year
- One Bootloader to Load Them All - Research materials, Code , Etc.☆51Updated 2 years ago
- SRE - Dissecting Malware for Static Analysis & the Complete Command-line Tool☆52Updated 2 months ago
- NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection☆29Updated last year
- Linux rootkit for educational purposes☆30Updated 11 months ago
- Just another elf parser☆22Updated last year
- Exploit POC for CVE-2024-36877☆46Updated 6 months ago
- PoC code and tools for Black Hat USA 2024☆17Updated 7 months ago
- A few examples of how to trap virtual memory access on Windows.☆27Updated 2 months ago
- Evasive ELF Static PIE User-Land-Exec featured in Tmpout Vol 1.☆25Updated 3 years ago
- Michelangelo REanimator bootkit and REcon 2023 talk slides/materials☆28Updated last year
- yet another hidden LKM hunter☆18Updated last year
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆46Updated this week
- ELF binary forensics tool for APT, virus, backdoor and rootkit detection☆46Updated 4 months ago
- Linux Kernel module-less implant (backdoor)☆72Updated 4 years ago
- GarbageMan is a set of tools for analyzing .NET binaries through heap analysis.☆115Updated last year
- A utility to fix intentionally corrupted UPX packed files.☆83Updated last year
- using the gpu to hide your payload☆55Updated 2 years ago
- SMM UEFI module and client for UMD privilege escalation☆33Updated last year
- ☆27Updated 3 months ago
- Loads a program into a memfd and runs it.☆12Updated 2 years ago
- anti-ransomware file-system filter☆57Updated 6 months ago
- ☆32Updated last year
- GERMY is a Linux Kernel n-day in the N_GSM line discipline☆45Updated 9 months ago
- An example of hijacking the dynamic linker with a custom interpreter who loads and executes modular viruses☆62Updated 3 years ago
- A feed of malware samples curated from threat intelligence sources.☆25Updated last year
- A payload delivery system which embeds payloads in an executable's icon file!☆72Updated last year
- Linux kernel LPE practice with an NPD vulnerability☆36Updated last year