bluedragonsecurity / bds_userland
Linux userland rootkit. Hides file and directory, hides process, hides bind shell port, hides daemon port, hides reverse shell port, cleans up bash history and logs during installation
☆12Updated last year
Alternatives and similar repositories for bds_userland
Users that are interested in bds_userland are comparing it to the libraries listed below
Sorting:
- ☆30Updated last year
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆55Updated last week
- Efficient RAT signature locator for bypassing AV/EDR, supporting static scanning and memory scanning.☆42Updated 6 months ago
- Beacon compiled using clang☆66Updated 2 years ago
- An implementation of an indirect system call☆126Updated last year
- shellcode-loaders and beacon-loaders☆64Updated last year
- Use COM Component Bypass UAC,Dll Version☆34Updated 4 years ago
- vehsyscall:a syscall project that may bypass EDR☆59Updated last year
- Client/server code that impersonates TLS 1.3 to disguise C2 activity.☆68Updated 2 years ago
- Hide Port In Windows☆38Updated 6 months ago
- Loading Fileless Remote PE from URI to memory with argument passing and ETW patching and NTDLL unhooking and No New Thread technique☆63Updated 2 years ago
- My personal shellcode loader☆31Updated 2 years ago
- Convert PE files to a shellcode☆75Updated 5 years ago
- 简单安排一下 autochk.sys 这个rootkit☆71Updated 2 years ago
- shellcode生成框架☆85Updated 10 months ago
- Just another version of the custom stack call from Proxy-Function-Calls-For-ETwTI☆34Updated 2 years ago
- ☆40Updated 3 years ago
- ☆26Updated last year
- Self Cleanup in post-ex job☆55Updated 8 months ago
- Load static-compiled PE from remote server.☆61Updated 3 years ago
- ☆91Updated 3 years ago
- ☆32Updated 4 years ago
- Kill Protected Process Light Process (include av)☆56Updated last year
- A method to execute syscalls while bypassing EDR's function hooking and call stack analysis.☆13Updated 2 weeks ago
- frida based script which automates the process of discovering and exploiting DLL Hijacks in target binaries. The discovered binaries can …☆51Updated 2 years ago
- Windows Defender VDM lua collections☆47Updated 2 years ago
- ☆37Updated 5 years ago
- power-kill is a project that kill protected processes (such as EDR or AV) by injecting shellcode into high privilege processes☆46Updated 3 years ago
- Shellcode implementation of Reflective DLL Injection by Golang. Convert DLLs to position independent shellcode☆60Updated 4 years ago
- It stinks☆102Updated 3 years ago