ilammy / ftrace-hook
Using ftrace for function hooking in Linux kernel
☆252Updated 3 years ago
Related projects: ⓘ
- Linux Kernel hooking engine (x86)☆323Updated 4 months ago
- kprobes template☆50Updated 3 years ago
- linux elf injector for x86 x86_64 arm arm64☆309Updated 6 years ago
- minivm based on kvm☆142Updated 3 months ago
- Advanced process execution monitoring utility for linux (procmon like)☆84Updated 8 years ago
- A small kernel module that can hook arbitrary syscalls on x86_64☆47Updated 4 years ago
- KVM-based Virtual Machine Introspection☆305Updated 2 weeks ago
- POSIX Function tracing☆324Updated 7 years ago
- Secure ELF parsing/loading library for forensics reconstruction of malware, and robust reverse engineering tools☆408Updated last month
- A ptrace library for easy syscall injection in Linux.☆165Updated 2 months ago
- a lightweight library to parse Linux's /proc/[pid]/maps file, which contains the memory map of a process☆119Updated 3 weeks ago
- hook or replace arbitary linux kernel functions in runtime, supporting arm32, arm64, x86, x86_64☆145Updated 2 weeks ago
- 抽出KVM代码进行注释☆60Updated 6 years ago
- Linux based inter-process code injection without ptrace(2)☆235Updated 7 years ago
- Examples for: Learning KVM - implement your own kernel☆351Updated last year
- A small library to modify all page-table levels of all processes from user space for x86_64 and ARMv8.☆230Updated last month
- A collection of eBPF programs demonstrating bad behavior, presented at DEF CON 29☆530Updated 2 months ago
- Dectect syscall hooking using eBPF☆139Updated last year
- Study blog. Much more about KVM/Kernel/Virtualization.☆65Updated this week
- A minimal kvm example