khale / elf-hijack
Example of using ELF hacking to inject malicious code into a target binary
☆21Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for elf-hijack
- Experiment with Linux system calls (memfd_create, fexecve, fork...)☆21Updated 5 years ago
- Tool to extract the kallsyms (System.map) from a memory dump☆24Updated last year
- A dynamically loadable virtual-machine based rootkit designed for Linux Kernel v5.13.0 using AMD-V (SVM).☆27Updated 2 years ago
- A collection of Linux kernel rootkits found across the internet taken and put together☆74Updated 2 years ago
- Configure SPI flash write protection.☆23Updated 4 years ago
- Static analysis tool based on clang, which detects source-to-binary information leaks in C and C++ projects☆80Updated 2 years ago
- VSCode dark theme for IDA 7.3☆27Updated 3 years ago
- Syscall hooking for reverse-engineering and anti-debug bypass on Linux x86 32/64☆40Updated 4 years ago
- Code injection from Linux kernel to a process☆19Updated last year
- x86/x64 architecture plugin☆39Updated 8 months ago
- PPT of my talks.☆11Updated 3 years ago
- In line function hooking LKM rootkit☆51Updated 4 years ago
- A small fun project to protect a file from writing using ftrace hooking.☆23Updated 3 years ago
- Full-VM taint analysis with Xen, Intel(R) Processor Trace and Triton.☆39Updated last year
- LibVMI in MiniOS☆12Updated 3 years ago
- Helper script for Linux kernel disassemble or debugging with IDA Pro on VMware + GDB stub (including some symbols helpers)☆36Updated last year
- AMD SVM hypervisor rootkit proof of concept☆42Updated last year
- Build your emulation environment as needed☆64Updated 3 years ago
- ☆32Updated 3 years ago
- clone of armadillo patched for windows☆46Updated 3 weeks ago
- Rizin FLIRT Signature Database☆37Updated last year
- An example of hijacking the dynamic linker with a custom interpreter who loads and executes modular viruses☆60Updated 2 years ago
- Collection of simple anti-debugging tricks for Linux☆55Updated 6 years ago
- Tools for Linux kernel debugging on Bochs (including symbols, native Bochs debugger and IDA PRO)☆31Updated last year
- ☆39Updated 3 years ago
- A fast execution trace symbolizer for Windows.☆130Updated 6 months ago
- Notes on QEMU and Debian MIPS (big-endian)☆43Updated 6 years ago
- ☆46Updated 2 years ago
- hypervisor enforced patch protection for the linux kernel with xen + libvmi, libvmi KASLR offset spoofer☆29Updated 6 months ago
- LLVM based devirtualization PoC’s.☆20Updated 2 years ago