ilammy / ftrace-hookLinks
Using ftrace for function hooking in Linux kernel
☆284Updated 4 years ago
Alternatives and similar repositories for ftrace-hook
Users that are interested in ftrace-hook are comparing it to the libraries listed below
Sorting:
- Linux Kernel hooking engine (x86)☆369Updated last week
- kprobes template☆60Updated 4 years ago
- A small kernel module that can hook arbitrary syscalls on x86_64☆52Updated 6 years ago
- linux elf injector for x86 x86_64 arm arm64☆338Updated 7 years ago
- POSIX Function tracing☆339Updated 8 years ago
- hook or replace arbitary linux kernel functions in runtime, supporting arm32, arm64, x86, x86_64☆204Updated 4 months ago
- Secure ELF parsing/loading library for forensics reconstruction of malware, and robust reverse engineering tools☆448Updated 5 months ago
- a linux kernel function inline hooking library☆30Updated 8 years ago
- Dectect syscall hooking using eBPF☆162Updated 2 years ago
- Linux based inter-process code injection without ptrace(2)☆253Updated 8 years ago
- KVM-based Virtual Machine Introspection☆351Updated last week
- Study blog. Much more about KVM/Kernel/Virtualization.☆76Updated 5 months ago
- A ptrace library for easy syscall injection in Linux.☆181Updated last year
- A network interface for GDB for Linux Kernel☆71Updated 2 months ago
- Advanced process execution monitoring utility for linux (procmon like)☆85Updated 9 years ago
- Transform vmlinuz into a fully debuggable vmlinux that can be used with /proc/kcore☆132Updated last year
- a lightweight library to parse Linux's /proc/[pid]/maps file, which contains the memory map of a process☆132Updated last year
- Examples for: Learning KVM - implement your own kernel☆379Updated 2 years ago
- small elf loader☆166Updated last year
- ☆28Updated 3 years ago
- A LKM rootkit for most newer kernel versions.☆178Updated 8 years ago
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆666Updated last year
- A small library to modify all page-table levels of all processes from user space for x86_64 and ARMv8.☆267Updated 6 months ago
- A tiny debugger implement the GDB Remote Serial Protocol. Can work on i386, x86_64, ARM and PowerPC.☆170Updated 3 years ago
- Tool tracing syscalls in a fast way using eBPF linux kernel feature☆99Updated 2 years ago
- 抽出KVM代码进行注释☆60Updated 7 years ago
- qemu源码的阅读笔记☆88Updated last year
- A simple in-kernel tcp client and server implemented as LKMs☆56Updated last year
- Code snippets from the O'Reilly book☆18Updated 3 years ago
- A small fun project to protect a file from writing using ftrace hooking.☆24Updated 4 years ago