jha / linux-kernel-hookLinks
A small kernel module that can hook arbitrary syscalls on x86_64
☆52Updated 6 years ago
Alternatives and similar repositories for linux-kernel-hook
Users that are interested in linux-kernel-hook are comparing it to the libraries listed below
Sorting:
- Using ftrace for function hooking in Linux kernel☆294Updated 4 years ago
- Obfuscates dynamic symbol table☆136Updated 7 years ago
- Linux Kernel hooking engine (x86)☆385Updated 2 months ago
- ELF packer - x86_64☆74Updated 10 years ago
- Secure ELF parsing/loading library for forensics reconstruction of malware, and robust reverse engineering tools☆449Updated 3 weeks ago
- linux elf injector for x86 x86_64 arm arm64☆344Updated 7 years ago
- Linux based inter-process code injection without ptrace(2)☆255Updated 8 years ago
- ELF Shared library injector using DT_NEEDED precedence infection. Acts as a permanent LD_PRELOAD☆112Updated 5 years ago
- Collection of simple anti-debugging tricks for Linux☆59Updated 7 years ago
- ☆426Updated 4 years ago
- Resources About Dynamic Binary Instrumentation and Dynamic Binary Analysis☆138Updated 5 years ago
- POSIX Function tracing☆339Updated 8 years ago
- Materials for LIEF tutorials☆154Updated 2 years ago
- writings on anti-reverse engineering.☆290Updated 4 years ago
- ☆181Updated 7 years ago
- load so file into current memory space and run function☆110Updated 8 years ago
- Automatically exported from code.google.com/p/hyperdbg☆109Updated 10 years ago
- Recover 64 bit ELF executables from memory dump☆93Updated 7 years ago
- Log data to/from SSL_write/SSL_read to disk using LD_PRELOAD hooks☆94Updated 6 years ago
- Dectect syscall hooking using eBPF☆167Updated 2 years ago
- A LKM rootkit for most newer kernel versions.☆180Updated 8 years ago
- IDA Signsrch☆159Updated 10 years ago
- Another kernel self protection☆62Updated 5 years ago
- ☆230Updated 3 years ago
- a linux kernel function inline hooking library☆30Updated 8 years ago
- Malicious use of ELF such as .so inject, func hook and so on.☆77Updated 8 years ago
- Shadow-Box: Lightweight and Practical Kernel Protector for x86 (Presented at BlackHat Asia 2017/2018, beVX 2018 and HITBSecConf 2017)☆188Updated 6 years ago
- a lightweight library to parse Linux's /proc/[pid]/maps file, which contains the memory map of a process☆134Updated last year
- A ptrace library for easy syscall injection in Linux.☆184Updated last year
- extended core file snapshot format☆230Updated 6 years ago