khale / elf-hijack
Example of using ELF hacking to inject malicious code into a target binary
☆22Updated 5 years ago
Alternatives and similar repositories for elf-hijack
Users that are interested in elf-hijack are comparing it to the libraries listed below
Sorting:
- Experiment with Linux system calls (memfd_create, fexecve, fork...)☆22Updated 6 years ago
- An example of hijacking the dynamic linker with a custom interpreter who loads and executes modular viruses☆64Updated 3 years ago
- A dynamically loadable virtual-machine based rootkit designed for Linux Kernel v5.13.0 using AMD-V (SVM).☆29Updated 2 years ago
- CreateRemoteThread for Linux☆38Updated 5 years ago
- Code injector for ELF binaries (incl. PIE)☆27Updated 7 years ago
- ugly code to check linux kernel memory and dump some internal structures☆46Updated 5 months ago
- Code injection from Linux kernel to a process☆21Updated last year
- LLVM pass that obfuscates against symbolic execution☆75Updated 6 years ago
- A collection of Linux kernel rootkits found across the internet taken and put together☆73Updated 2 years ago
- A C library for creating and using TCP/IP packets with raw network sockets☆66Updated 4 months ago
- Helper scripts for windows debugging with symbols for Bochs and IDA Pro (PDB files). Very handy for user mode <--> kernel mode☆19Updated last year
- Another (bad) ROP gadget finder, but this time in Rust☆20Updated last year
- ☆33Updated 3 years ago
- ☆37Updated 2 years ago
- Helper script for Linux kernel disassemble or debugging with IDA Pro on VMware + GDB stub (including some symbols helpers)☆36Updated last year
- PoC for a kernel rootkit☆9Updated 5 years ago
- Collection of simple anti-debugging tricks for Linux☆55Updated 7 years ago
- ELF Shared library injector using DT_NEEDED precedence infection. Acts as a permanent LD_PRELOAD☆110Updated 5 years ago
- Configure SPI flash write protection.☆23Updated 5 years ago
- IDA Database Parser for Rust☆25Updated 8 months ago
- Hooking the GDT - Installing a Call Gate. POC for Rootkit Arsenal Book Second Edition (version 2022)☆72Updated last year
- Binary Ninja plugin to perform automated analysis of Windows drivers☆17Updated 5 years ago
- Static analysis tool based on clang, which detects source-to-binary information leaks in C and C++ projects☆85Updated 2 years ago
- Source code on the 1.44MB 3.5 floppy accompanying the Windows NT File System Internals book.☆16Updated 5 years ago
- An ELF loader capable of manually loading ELF executables directly from memory into a new process, without the use of exec.☆51Updated 5 years ago
- A pykd maintenance fork☆44Updated 2 months ago
- An ELF / PE binary packer written in pure C, made for fun☆87Updated last year
- Rizin FLIRT Signature Database☆40Updated last year
- Abusing exceptions for code execution.☆111Updated 2 years ago
- x86/x64 architecture plugin☆39Updated last year