jha / linux-kernel-hook
A small kernel module that can hook arbitrary syscalls on x86_64
☆52Updated 5 years ago
Alternatives and similar repositories for linux-kernel-hook:
Users that are interested in linux-kernel-hook are comparing it to the libraries listed below
- ELF packer - x86_64☆72Updated 9 years ago
- Using ftrace for function hooking in Linux kernel☆267Updated 4 years ago
- ELF Shared library injector using DT_NEEDED precedence infection. Acts as a permanent LD_PRELOAD☆110Updated 5 years ago
- Security Evaluation of Dynamic Binary Instrumentation Engines☆80Updated 6 years ago
- ELF obfuscator☆65Updated 9 years ago
- MrsPicky - An IDAPython decompiler script that helps auditing memcpy() and memmove() calls☆123Updated last year
- BPF Processor for IDA Python☆51Updated 6 years ago
- ☆85Updated 8 years ago
- Fast static binary instrumentation for linux/x86☆82Updated 8 years ago
- An IDA file loader for Mobicore trustlet and driver binaries☆59Updated 5 years ago
- Shadow-Box: Lightweight and Practical Kernel Protector for x86 (Presented at BlackHat Asia 2017/2018, beVX 2018 and HITBSecConf 2017)☆185Updated 5 years ago
- Obfuscates dynamic symbol table☆134Updated 6 years ago
- Syscall table hook frame in Android kernel for arm and arm64☆82Updated 7 years ago
- Changing memory protection in an arbitrary process☆47Updated 6 years ago
- Heap analysis tooling for ptmalloc☆44Updated 2 years ago
- DynamoRIO plugin to get ASAN and SanitizerCoverage compatible output for closed-source executables☆207Updated 3 years ago
- a linux kernel function inline hooking library☆30Updated 7 years ago
- ☆136Updated 3 years ago
- Implementation of a thin hypervisor☆42Updated 8 years ago
- ☆55Updated 7 years ago
- Linux based inter-process code injection without ptrace(2)☆245Updated 7 years ago
- Recover 64 bit ELF executables from memory dump☆87Updated 6 years ago
- Kernel driver to fuzz Hyper-V hypercalls☆137Updated 6 years ago
- Resources About Dynamic Binary Instrumentation and Dynamic Binary Analysis☆133Updated 5 years ago
- GDB plugin peda for arm☆146Updated 3 months ago
- An IDA processor for eBPF bytecode☆47Updated 3 years ago
- Advanced process execution monitoring utility for linux (procmon like)☆84Updated 9 years ago
- Linux kernel rootkit to hide certain files and processes.☆36Updated 11 years ago
- Transform vmlinuz into a fully debuggable vmlinux that can be used with /proc/kcore☆130Updated 6 months ago
- gdbida - a visual bridge between a GDB session and IDA Pro's disassembler☆181Updated 6 years ago