daveti / syscallh
syscall hijacking in 2019
☆11Updated 6 years ago
Alternatives and similar repositories for syscallh:
Users that are interested in syscallh are comparing it to the libraries listed below
- Kernel function hooking using exception tables☆27Updated 6 years ago
- a linux kernel function inline hooking library☆30Updated 7 years ago
- PoC multi-layer protector for ELF32 x86 binaries☆10Updated 3 years ago
- Heap analysis tooling for ptmalloc☆44Updated 2 years ago
- Helper script for Linux kernel disassemble or debugging with IDA Pro on VMware + GDB stub (including some symbols helpers)☆36Updated last year
- PoC for obfuscating the dynamic symbol table injecting a custom Hash Table to do symbol resolution☆27Updated 4 years ago
- Rootkit breaker - experimental Linux anti-rootkit tool based on kprobes☆12Updated 4 years ago
- ELF Virus infection techniques that work with SCOP (Secure code partitioned) executables☆15Updated 5 years ago
- Dynamic binary translator for x86 binaries☆34Updated last year
- ELF Shared library injector using DT_NEEDED precedence infection. Acts as a permanent LD_PRELOAD☆109Updated 4 years ago
- x86 Dynamic Binary Translator Library☆34Updated 4 years ago
- Decode machine code into VEX IR and translate into LLVM IR☆25Updated 5 years ago
- PPT of my talks.☆11Updated 3 years ago
- Simple ELF tools written to demonstrate libelfmaster capabilities.☆39Updated 6 years ago
- Yet Another ELF-Injector☆16Updated 5 years ago
- IDA Pro Python plugin to analyze and annotate Linux kernel alternatives☆22Updated 3 years ago
- Using LibVMI to detect malware☆31Updated 2 years ago
- Changing memory protection in an arbitrary process☆47Updated 6 years ago
- Fast Binary Translator for the Kernel☆27Updated 11 years ago
- A dynamically loadable virtual-machine based rootkit designed for Linux Kernel v5.13.0 using AMD-V (SVM).☆29Updated 2 years ago
- Dump page tables on various OSes and analyze them☆28Updated 9 years ago
- Rootkit spotter - experimental Linux rootkit finder LKM☆27Updated 4 years ago
- Windows Application Loader Running *.Exe files in Memory against Scrylla☆21Updated 5 years ago
- Tool to extract the kallsyms (System.map) from a memory dump☆25Updated last year
- An Integrity-Check Monitoring Pintool☆56Updated 4 years ago
- LD_PRELOAD hook to trace malloc and free☆44Updated 7 years ago
- Plugin Manager for IDA Pro☆9Updated 9 years ago
- Qiling Framework Documentation☆15Updated 11 months ago
- Tools for Linux kernel debugging on Bochs (including symbols, native Bochs debugger and IDA PRO)☆31Updated last year
- python library for dumping a linux process from memory☆34Updated 14 years ago