landhb / DrawBridge
Layer 4 Single Packet Authentication Linux kernel module utilizing Netfilter hooks and kernel supported Berkeley Packet Filters (BPF)
☆114Updated last year
Alternatives and similar repositories for DrawBridge
Users that are interested in DrawBridge are comparing it to the libraries listed below
Sorting:
- Linux 4.9 Loadable Kernel Module to hide processes from system utilities☆67Updated 6 years ago
- Whitelisting LD_PRELOAD libraries using LD_AUDIT☆63Updated 3 years ago
- Rootkit Detector for UNIX☆61Updated last year
- ICMP and DNS tunneling via IPv4 and IPv6☆205Updated last month
- Small tool to run ELF binaries from memory with a given process name☆166Updated 3 years ago
- Tool to examine the behaviour of setuid binaries under constrained limits.☆61Updated 4 years ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆131Updated 2 years ago
- ELF Shared library injector using DT_NEEDED precedence infection. Acts as a permanent LD_PRELOAD☆110Updated 5 years ago
- A ptrace POC by hooking SSH to reveal provided passwords☆181Updated 8 years ago
- crypted admin shell: SSH-like strong crypto remote admin shell for Linux, BSD, Android, Solaris and OSX☆194Updated last week
- Example program using eBPF to log data being based in using shell pipes☆41Updated 4 years ago
- General Research Repository - Only updated when I feel like it☆28Updated 6 months ago
- ELF anti-forensics exec, for injecting full dynamic executables into process image (With thread injection)☆135Updated 7 years ago
- LKRG bypass methods☆72Updated 5 years ago
- Security For Embedeed Systems - One Bin to Rule Them All.☆150Updated 6 years ago
- eBPF - extended Berkeley Packet Filter tooling☆123Updated 2 years ago
- Linux v4.x.x Rootkit☆90Updated 9 months ago
- Linux Rootkit Scanner☆88Updated 3 years ago
- E2E encryption for multi-hop tty sessions or portshells + TCP/UDP port forward☆121Updated 6 months ago
- A toy CTF Golang Reverse Shell w/ a Tmux-driven psuedo-C2 Interface☆87Updated last month
- Shadow-Box: Lightweight and Practical Kernel Protector for x86 (Presented at BlackHat Asia 2017/2018, beVX 2018 and HITBSecConf 2017)☆185Updated 5 years ago
- (Linux Kernel) Stack Monitoring Tool☆45Updated 3 years ago
- kprochide is an LKM for hiding processes from the userland. The module is able to hide multiple processes and is able to dynamically rece…☆21Updated 4 years ago
- Binary Protocol Differ☆118Updated 4 years ago
- ☆92Updated 7 years ago
- Fully functional but simplified Linux Kernel Module (LKM) Rootkit for educational purposes☆61Updated 6 years ago
- SSH Tunnelling in "RAW mode", via STDIN/OUT without using forwarding channels☆109Updated 6 years ago
- Implementation of the SMM rootkit "The Watcher"☆126Updated 3 years ago
- Disabling kernel lockdown on Ubuntu without physical access☆79Updated 2 years ago
- DNS packet generator☆46Updated 9 months ago