compilepeace / EVIL_RABBITLinks
-x-x-x- DO NOT RUN ON PRODUCTION MACHINE -x-x-x- LD_PRELOAD based user-land rootkit for Linux platform.
☆28Updated 4 years ago
Alternatives and similar repositories for EVIL_RABBIT
Users that are interested in EVIL_RABBIT are comparing it to the libraries listed below
Sorting:
- A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malwar…☆129Updated 4 years ago
- ☆28Updated 6 years ago
- Proxy system calls over an RPC channel☆99Updated 3 years ago
- ☆137Updated 7 months ago
- Proof of concept for injecting simple shellcode via ptrace into a running process.☆72Updated 3 years ago
- A summary about different projects/presentations/tools to test how to evade malware sandbox systems☆55Updated 6 years ago
- In line function hooking LKM rootkit☆51Updated 5 years ago
- Linux Rootkits (4.x Kernel)☆86Updated 4 years ago
- An attempt to restore and adapt to modern Win10 version the 'Rootkit Arsenal' original code samples☆73Updated 3 years ago
- Raw socket library/framework for red team events☆34Updated 2 years ago
- Code snippets for bare-metal malware development☆98Updated 3 years ago
- bdvl☆114Updated 3 years ago
- Gozi ISFB is a well-known and widely distributed banking trojan, and has been in the threat landscape for the past several years.☆65Updated 7 years ago
- The following repository contains a modified version of SUNBURST with cracekd hashes, comments and annotations.☆56Updated 4 years ago
- ☆64Updated last year
- Binary to shellcode from an object/executable format 32 & 64-bit PE , ELF☆74Updated 4 years ago
- A repository where I share my injection implemintations☆29Updated 5 years ago
- ☆67Updated 2 years ago
- ☆90Updated 5 years ago
- Winsock accept() Backdoor Implant.☆118Updated 4 years ago
- ☆48Updated 3 years ago
- Sentello is python script that simulates the anti-evasion and anti-analysis techniques used by malware.☆75Updated 4 years ago
- "An Introduction to Windows Exploit Development" is an open sourced, free Windows exploit development course I created for the Southeast …☆41Updated 5 years ago
- LD_PRELOAD rootkit☆137Updated last year
- ELF launcher for encrypted binaries decrypted on-the-fly and executed in memory☆26Updated 5 years ago
- A C++ POC for process injection using NtCreateSectrion, NtMapViewOfSection and RtlCreateUserThread. Credit to @spotheplanet for his notes…☆43Updated 4 years ago
- A ptrace POC by hooking SSH to reveal provided passwords☆187Updated 8 years ago
- A local LKM rootkit loader/dropper that lists available security mechanisms☆52Updated 4 years ago
- Red Team Operator: Malware Development Essentials Course☆100Updated 5 years ago
- Recreating and reviewing the Windows persistence methods☆39Updated 3 years ago