Red-Team LKM
☆653May 31, 2026Updated last month
Alternatives and similar repositories for KoviD
Users that are interested in KoviD are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Linux Loadable Kernel Module (LKM) based rootkit (ring-0), capable of hiding itself, processes/implants, rmmod proof, has ability to bypa…☆274Dec 6, 2025Updated 7 months ago
- LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)☆2,425Apr 27, 2026Updated 3 months ago
- awesome-linux-rootkits☆2,087Feb 15, 2026Updated 5 months ago
- A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.☆1,975Apr 7, 2024Updated 2 years ago
- Linux Kernel Hacking☆766Apr 10, 2024Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Rootkit spotter - experimental Linux rootkit finder LKM☆31Oct 11, 2020Updated 5 years ago
- Collection of codes focused on Linux rootkits☆220Oct 22, 2025Updated 9 months ago
- Linux Sleep Obfuscation☆130Jan 7, 2024Updated 2 years ago
- A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs☆340Feb 27, 2026Updated 5 months ago
- Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.☆384Aug 29, 2025Updated 11 months ago
- Experimental Windows x64 Kernel Rootkit with anti-rootkit evasion features.☆613Aug 2, 2025Updated 11 months ago
- Dectect syscall hooking using eBPF☆169Apr 28, 2023Updated 3 years ago
- Pack/Encrypt/Obfuscate ELF + SHELL scripts☆455Apr 11, 2026Updated 3 months ago
- The LKM rootkit working in Linux Kernels 2.6.x/3.x/4.x/5.x☆141Aug 8, 2023Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again.☆86Feb 28, 2025Updated last year
- Stealthy Linux Kernel Rootkit for modern kernels (6x)☆1,722Jun 11, 2026Updated last month
- yet another hidden LKM hunter☆31Sep 18, 2025Updated 10 months ago
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆133Apr 13, 2025Updated last year
- A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.☆891Mar 21, 2025Updated last year
- A COFF loader made in Rust☆345Mar 14, 2026Updated 4 months ago
- Windows Kernel Rootkit in Rust☆704Oct 10, 2025Updated 9 months ago
- Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.☆2,443Jun 26, 2026Updated last month
- A tool employs direct registry manipulation to create scheduled tasks without triggering the usual event logs.☆632Jan 2, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- LD_PRELOAD Rootkit☆330Apr 5, 2025Updated last year
- Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.☆1,675Oct 19, 2023Updated 2 years ago
- ebpfkit is a rootkit powered by eBPF☆854Feb 28, 2023Updated 3 years ago
- Linux Kernel module-less implant (backdoor)☆73Mar 11, 2021Updated 5 years ago
- An EDR bypass that prevents EDRs from hooking or loading DLLs into our process by hijacking the AppVerifier layer☆555Feb 13, 2024Updated 2 years ago
- A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malwar…☆136Sep 19, 2021Updated 4 years ago
- A technique that can be used to bypass AV/EDR memory scanners. This can be used to hide well-known and detected shellcodes (such as msfve…☆598Jun 12, 2024Updated 2 years ago
- A Rust implementation of GodPotato — abusing SeImpersonate to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTA…☆367Mar 17, 2026Updated 4 months ago
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆695Jul 7, 2024Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Linux Kernel hooking engine (x86)☆391Oct 14, 2025Updated 9 months ago
- Demonized Shell is an Advanced Tool for persistence in linux.☆455Jan 5, 2025Updated last year
- A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Cal…☆265Jun 10, 2025Updated last year
- Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.☆2,182Updated this week
- Realm is a cross platform Red Team engagement platform with a focus on automation and reliability.☆632Jul 17, 2026Updated last week
- Load a dynamic library from memory by modifying the native Windows loader☆305May 5, 2026Updated 2 months ago
- A memory-based evasion technique which makes shellcode invisible from process start to end.☆1,200Oct 16, 2023Updated 2 years ago