h3xduck / Umbra
A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.
☆122Updated 3 years ago
Alternatives and similar repositories for Umbra:
Users that are interested in Umbra are comparing it to the libraries listed below
- A local LKM rootkit loader/dropper that lists available security mechanisms☆52Updated 3 years ago
- LD_PRELOAD rootkit☆131Updated last year
- BPFDoor Source Code. Originally found from Chinese Threat Actor Red Menshen☆43Updated 2 years ago
- A Flask-based HTTP(S) command and control (C2) with a web frontend. Malleable agent written in Go.☆36Updated last year
- Evasion Escaper is a project aimed at evading the checks that malicious software performs to detect if it's running in a virtual environm…☆105Updated last month
- Stealthy Loader-cum-dropper/stage-1/stager targeting Windows10☆38Updated 2 years ago
- bdvl☆113Updated 3 years ago
- -x-x-x- DO NOT RUN ON PRODUCTION MACHINE -x-x-x- LD_PRELOAD based user-land rootkit for Linux platform.☆27Updated 4 years ago
- A Flask-based HTTP(S) command and control (C2) framework with a web interface. Custom Windows EXE/DLL implants written in C++. For educat…☆90Updated last year
- A repository dedicated to researching, documenting, developing, and ultimately, defending against various strains of malicious software.☆30Updated this week
- Bypass Malware Sandbox Evasion Ram check☆137Updated 2 years ago
- Malware indetectable, with AV bypass techniques, anti-disassembly, etc.☆90Updated 4 years ago
- Simple PoC Python agent to showcase Havoc C2's custom agent interface. Not operationally safe or stable. Released with accompanying blog …☆80Updated last year
- (Sim)ulate (Ba)zar Loader☆29Updated 4 years ago
- A C2 framework for initial access in Go☆177Updated 2 years ago
- Finding secrets in kernel and user memory☆115Updated last year
- ☆112Updated 2 years ago
- Recreating and reviewing the Windows persistence methods☆36Updated 3 years ago
- It's pointy and it hurts!☆124Updated 2 years ago
- Linux Kernel module-less implant (backdoor)☆72Updated 4 years ago
- ☆67Updated last year
- Command & Control server and agent written in Rust☆36Updated 2 years ago
- The AMSI server for Avred☆29Updated last year
- Mochi is a proof-of-concept C++ loader that leverages the ChaiScript embedded scripting language to execute code.☆99Updated 3 years ago
- ☆157Updated last year
- Project for identifying executables and DLLs vulnerable to environment-variable based DLL hijacking.☆57Updated 2 years ago
- Simple ransomware written in Rust. Part of the building a rustomware blog post.☆32Updated last year
- Understanding WinRAR Code Execution Vulnerability (CVE-2023-38831)☆40Updated last year
- This is a simple example of DLL hijacking enabling proxy execution.☆66Updated last year
- A light C# implant that bypasses Windows Firewall and Defender☆22Updated 3 years ago