elfmaster / linker_preloading_virus
An example of hijacking the dynamic linker with a custom interpreter who loads and executes modular viruses
☆60Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for linker_preloading_virus
- In line function hooking LKM rootkit☆51Updated 4 years ago
- Code injection from Linux kernel to a process☆19Updated last year
- Linux Kernel module-less implant (backdoor)☆66Updated 3 years ago
- ELF binary forensics tool for APT, virus, backdoor and rootkit detection☆45Updated 2 weeks ago
- Evasive ELF Static PIE User-Land-Exec featured in Tmpout Vol 1.☆24Updated 3 years ago
- ☆44Updated 2 years ago
- ☆49Updated 4 years ago
- Matryoshka - stacked LKM loader☆50Updated last year
- Highly advanced Linux anti-exploitation and anti-tamper binary protector for ELF.☆152Updated 2 years ago
- A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malwar…☆119Updated 3 years ago
- A collection of Linux kernel rootkits found across the internet taken and put together☆74Updated 2 years ago
- -x-x-x- DO NOT RUN ON PRODUCTION MACHINE -x-x-x- LD_PRELOAD based user-land rootkit for Linux platform.☆26Updated 3 years ago
- A utility to fix intentionally corrupted UPX packed files.☆80Updated last year
- ELF Virus infection techniques that work with SCOP (Secure code partitioned) executables☆14Updated 5 years ago
- ☆26Updated 5 years ago
- Shiva is a programmable dynamic linker for loading ELF microprograms☆28Updated last year
- SPI flash read MitM attack PoC☆36Updated 2 years ago
- Rootkit spotter - experimental Linux rootkit finder LKM☆25Updated 4 years ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆69Updated last year
- call gates as stable comunication channel for NT x86 and Linux x86_64☆30Updated last year
- Poc for ELF64 runtime infection via GOT poisoning technique by elfmaster☆29Updated 4 years ago
- Static analysis tool based on clang, which detects source-to-binary information leaks in C and C++ projects☆80Updated 2 years ago
- Michelangelo REanimator bootkit and REcon 2023 talk slides/materials☆29Updated 8 months ago
- Exploits pack for the Windows Kernel mode driver HackSysExtremeVulnerableDriver written for educational purposes.☆63Updated 3 years ago
- ☆16Updated 4 years ago
- Exercises from Designing BSD Rootkits working in 2020 with FreeBSD 12.2☆45Updated 2 years ago
- BPFDoor Source Code. Originally found from Chinese Threat Actor Red Menshen☆40Updated 2 years ago
- ☆14Updated 2 years ago
- Abusing exceptions for code execution.☆107Updated last year
- ☆74Updated 2 months ago