bluedragonsecurity / bds_lkm_ftrace
Ftrace Based Linux Loadable Kernel Module Rootkit for Linux Kernel 5.x and 6.x on x86_64, hides files, hides process, hides bind shell & reverse shell port, privilege escalation, cleans up logs and bash history during installation
☆17Updated last year
Alternatives and similar repositories for bds_lkm_ftrace:
Users that are interested in bds_lkm_ftrace are comparing it to the libraries listed below
- Evasive ELF Static PIE User-Land-Exec featured in Tmpout Vol 1.☆26Updated 3 years ago
- Code injection from Linux kernel to a process☆20Updated last year
- Repository of vulnerabilities disclosed by ESET☆28Updated 2 years ago
- One Bootloader to Load Them All - Research materials, Code , Etc.☆51Updated 2 years ago
- rpv-web is a browser based frontend for the rpv library☆24Updated 2 weeks ago
- A few examples of how to trap virtual memory access on Windows.☆29Updated 4 months ago
- NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection☆29Updated last year
- PoC code and tools for Black Hat USA 2024☆21Updated 8 months ago
- yet another hidden LKM hunter☆21Updated last year
- Michelangelo REanimator bootkit and REcon 2023 talk slides/materials☆28Updated last year
- Slides from various conference talks☆36Updated last year
- Just another elf parser☆23Updated last year
- Yet another Windows DLL injector.☆39Updated 3 years ago
- Exploiting ring0 memcpy-like functionality to disable Driver Signing Enforcement (DSE)☆20Updated 5 years ago
- Exploit POC for CVE-2024-36877☆46Updated 8 months ago
- ☆37Updated last month
- dk is a WinDbg extenion for dumping memory data in meaningful and organized ways, it is an enhancement of my previous tokenext project.☆24Updated last year
- BPFDoor Source Code. Originally found from Chinese Threat Actor Red Menshen☆45Updated 2 years ago
- A local LKM rootkit loader/dropper that lists available security mechanisms☆52Updated 3 years ago
- -x-x-x- DO NOT RUN ON PRODUCTION MACHINE -x-x-x- LD_PRELOAD based user-land rootkit for Linux platform.☆27Updated 4 years ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆72Updated last year
- SPI flash read MitM attack PoC☆37Updated 2 years ago
- ☆21Updated 3 years ago
- Report and exploit of CVE-2023-36427☆90Updated last year
- Binary Ninja plugin to deobfuscate strings obfuscated with the Garble project☆16Updated last month
- call gates as stable comunication channel for NT x86 and Linux x86_64☆31Updated last year
- Hardware Spoofing & VirtualBox-Hardening x64 Bootkit☆16Updated 2 years ago
- ☆28Updated 5 months ago
- Windows NTLM Authentication Backdoor☆15Updated 3 years ago
- ELF packer/crypter that aims to create hardened and stealthy troyans☆54Updated 3 years ago