bluedragonsecurity / bds_lkm_ftrace
Ftrace Based Linux Loadable Kernel Module Rootkit for Linux Kernel 5.x and 6.x on x86_64, hides files, hides process, hides bind shell & reverse shell port, privilege escalation, cleans up logs and bash history during installation
☆15Updated last year
Alternatives and similar repositories for bds_lkm_ftrace:
Users that are interested in bds_lkm_ftrace are comparing it to the libraries listed below
- Exploit POC for CVE-2024-36877☆46Updated 5 months ago
- Code injection from Linux kernel to a process☆19Updated last year
- Michelangelo REanimator bootkit and REcon 2023 talk slides/materials☆28Updated 10 months ago
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year
- BPFDoor Source Code. Originally found from Chinese Threat Actor Red Menshen☆43Updated 2 years ago
- rpv-web is a browser based frontend for the rpv library☆25Updated 6 months ago
- rekk is set of tools written in Rust to obfuscate ELF & PE executables with nanomites.☆29Updated last month
- Enabled / Disable LSA Protection via BYOVD☆65Updated 3 years ago
- One Bootloader to Load Them All - Research materials, Code , Etc.☆51Updated 2 years ago
- NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection☆30Updated last year
- SMM UEFI module and client for UMD privilege escalation☆30Updated last year
- Linux Kernel module-less implant (backdoor)☆69Updated 3 years ago
- A payload delivery system which embeds payloads in an executable's icon file!☆73Updated last year
- Report and exploit of CVE-2023-36427☆89Updated last year
- Linux kernel LPE practice with an NPD vulnerability☆36Updated last year
- Linux rootkit for educational purposes☆30Updated 10 months ago
- An initial proof of concept of a bootkit based on Cr4sh's DMABackdoorBoot☆61Updated last year
- A utility to fix intentionally corrupted UPX packed files.☆82Updated last year
- Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)☆20Updated 4 years ago
- Dataset of packed ELF samples☆18Updated last year
- HEVD Exploit: BufferOverflowNonPagedPoolNx on Windows 10 22H2 - Escalating from Low Integrity to SYSTEM via Aligned Chunk Confusion☆46Updated last week
- ☆25Updated 3 months ago
- Proof-of-Concept for CVE-2024-26218☆49Updated 9 months ago
- Matryoshka - stacked LKM loader☆50Updated last year
- yet another hidden LKM hunter☆17Updated last year
- An x64dbg plugin which marks XFG call signatures as data☆73Updated last year
- This IDA plugin extends the functionality of the assembly and hex view. With this plugin, you can conveniently decode/decrypt/alter data …☆75Updated 3 weeks ago
- SPI flash read MitM attack PoC☆37Updated 2 years ago
- An injector that use PT_LOAD technique☆12Updated 2 years ago
- A post-processing script for TinyTracer☆38Updated last year