landhb / DrawBridge
Layer 4 Single Packet Authentication Linux kernel module utilizing Netfilter hooks and kernel supported Berkeley Packet Filters (BPF)
☆112Updated last year
Related projects ⓘ
Alternatives and complementary repositories for DrawBridge
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆123Updated last year
- monitor and protect SSH sessions with eBPF☆65Updated 3 years ago
- eBPF - extended Berkeley Packet Filter tooling☆122Updated 2 years ago
- Linux 4.9 Loadable Kernel Module to hide processes from system utilities☆66Updated 6 years ago
- ICMP and DNS tunneling via IPv4 and IPv6☆199Updated last year
- crypted admin shell: SSH-like strong crypto remote admin shell for Linux, BSD, Android, Solaris and OSX☆190Updated last month
- Kernel-Mode Rootkit Hunter☆360Updated 2 years ago
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆113Updated last year
- Whitelisting LD_PRELOAD libraries using LD_AUDIT☆61Updated 3 years ago
- Example program using eBPF to log data being based in using shell pipes☆40Updated 3 years ago
- WhiteBeam: Transparent endpoint security☆96Updated last year
- A keystroke / terminal logger for Linux.☆212Updated 4 months ago
- Small tool to run ELF binaries from memory with a given process name☆150Updated 3 years ago
- Hide processes as a normal user in Linux.☆255Updated 4 months ago
- Rootkit Detector for UNIX☆61Updated last year
- Vault Exploit Defense☆123Updated 2 months ago
- A ptrace POC by hooking SSH to reveal provided passwords☆180Updated 7 years ago
- E2E encryption for multi-hop tty sessions or portshells + TCP/UDP port forward☆116Updated this week
- (Linux Kernel) Stack Monitoring Tool☆42Updated 2 years ago
- LKRG bypass methods☆71Updated 4 years ago
- SLAE Assignments☆39Updated 8 months ago
- disable LD_PRELOAD on linux☆20Updated 8 years ago
- bdvl☆107Updated 2 years ago
- This is a kernel module invoked reverse shell proof of concept.☆70Updated 5 years ago
- Tool to examine the behaviour of setuid binaries under constrained limits.☆62Updated 3 years ago
- LKM rootkit for Linux x86 with the 2.6 kernel. It inserts salts inside system_call and sysenter_entry.☆83Updated last year
- The first Linux hooking framework to allow merging two binary files into one!☆95Updated 4 years ago
- Linux Kernel Runtime Integrity with eBPF☆163Updated 11 months ago
- Yara powered NIDS with high speed packet capture powered by PF_RING☆66Updated 5 months ago