hardenedvault / ved-ebpf
VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF
☆156Updated 7 months ago
Alternatives and similar repositories for ved-ebpf:
Users that are interested in ved-ebpf are comparing it to the libraries listed below
- Linux Kernel Runtime Integrity with eBPF☆174Updated last year
- Dectect syscall hooking using eBPF☆151Updated last year
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆129Updated 2 years ago
- An eBPF playground☆205Updated last year
- ☆86Updated 9 months ago
- Vault Exploit Defense☆125Updated 7 months ago
- bpflock - eBPF driven security for locking and auditing Linux machines☆147Updated 3 years ago
- POC for Phantom Attack☆82Updated 2 years ago
- ☆301Updated last year
- Rust Linux Kernel Module designed for LKM rootkit detection☆39Updated last month
- Red Canary's eBPF Sensor☆103Updated 9 months ago
- eBPF hacks☆186Updated 4 months ago
- Slides & Hands-on for the reverse engineering workshop☆178Updated 2 years ago
- ☆122Updated last month
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆107Updated last week
- Linux based vulnerabilities (CVE) exploit detection through runtime security using Falco/Osquery/Yara/Sigma☆21Updated last year
- Damn Vulenerable Kernel Module for kernel fuzzing☆58Updated 5 months ago
- eBPF Memory Dump Tool☆64Updated last month
- Writeups, PoCs of the bugs I found while preparing for the Pwn2Own Miami 2023 contest targeting UaGateway from the OPC UA Server category…☆60Updated last year
- Linpmem is a linux memory acquisition tool☆82Updated 11 months ago
- Kubernetes offensive framework built in eBPF☆37Updated 2 years ago
- A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs☆286Updated 3 months ago
- kubernetes rootkit☆31Updated last year
- 🐝 Ransomware Detection using Machine Learning with eBPF for Linux.☆59Updated 4 months ago
- Disable SSL certificate verification for all binaries that use libssl☆49Updated 2 years ago
- A collection of bypasses and exploits for eBPF-based cloud security.☆21Updated last year
- Userland exec PoC to be used as attack vector technique☆84Updated 2 months ago
- VirtFuzz is a Linux Kernel Fuzzer that uses VirtIO to provide inputs into the kernels subsystem. It is built with LibAFL.☆119Updated 10 months ago
- https://breaking-bits.gitbook.io/breaking-bits/exploit-development/linux-kernel-exploit-development☆43Updated 3 years ago
- Kernel Read Write Execute☆41Updated 3 months ago