landhb / DrawBridge
Layer 4 Single Packet Authentication Linux kernel module utilizing Netfilter hooks and kernel supported Berkeley Packet Filters (BPF)
☆113Updated last year
Alternatives and similar repositories for DrawBridge:
Users that are interested in DrawBridge are comparing it to the libraries listed below
- Whitelisting LD_PRELOAD libraries using LD_AUDIT☆62Updated 3 years ago
- Linux 4.9 Loadable Kernel Module to hide processes from system utilities☆67Updated 6 years ago
- A ptrace POC by hooking SSH to reveal provided passwords☆181Updated 8 years ago
- eBPF - extended Berkeley Packet Filter tooling☆123Updated 2 years ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆129Updated 2 years ago
- Kernel-Mode Rootkit Hunter☆366Updated 3 years ago
- ICMP and DNS tunneling via IPv4 and IPv6☆205Updated 2 weeks ago
- ☆92Updated 7 years ago
- E2E encryption for multi-hop tty sessions or portshells + TCP/UDP port forward☆121Updated 5 months ago
- This is a kernel module invoked reverse shell proof of concept.☆72Updated 5 years ago
- A toy CTF Golang Reverse Shell w/ a Tmux-driven psuedo-C2 Interface☆87Updated last week
- egrets monitors egress☆45Updated 5 years ago
- Container for assorted volatility plugins.☆22Updated 11 years ago
- monitor and protect SSH sessions with eBPF☆68Updated 3 years ago
- Tool to examine the behaviour of setuid binaries under constrained limits.☆61Updated 4 years ago
- Example program using eBPF to log data being based in using shell pipes☆41Updated 4 years ago
- ELF anti-forensics exec, for injecting full dynamic executables into process image (With thread injection)☆135Updated 7 years ago
- SLAE Assignments☆39Updated last year
- kprochide is an LKM for hiding processes from the userland. The module is able to hide multiple processes and is able to dynamically rece…☆21Updated 4 years ago
- Rootkit Detector for UNIX☆61Updated last year
- out-of-tree kernel {module, exploit} development tool☆226Updated 4 months ago
- Application Layer IDS/IPS with iptables☆75Updated 6 years ago
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆116Updated 2 years ago
- DNS packet generator☆46Updated 8 months ago
- Linux kernel XFRM UAF poc (3.x - 5.x kernels)☆133Updated 5 years ago
- crypted admin shell: SSH-like strong crypto remote admin shell for Linux, BSD, Android, Solaris and OSX☆193Updated 6 months ago
- SSH Tunnelling in "RAW mode", via STDIN/OUT without using forwarding channels☆109Updated 6 years ago
- Small tool to run ELF binaries from memory with a given process name☆165Updated 3 years ago
- Fully functional but simplified Linux Kernel Module (LKM) Rootkit for educational purposes☆61Updated 5 years ago
- A server and client implementation to demonstrate and test ALG abuse and perform the NAT slipstream attack described https://www.samy.pl/…☆42Updated 4 years ago