maK- / Syscall-table-hijack-LKM
This demonstrates the hijacking of the "write" system call and how to set the System Call table to read/write mode via modifying the correct cr0 bit.
☆19Updated 10 years ago
Alternatives and similar repositories for Syscall-table-hijack-LKM:
Users that are interested in Syscall-table-hijack-LKM are comparing it to the libraries listed below
- Stealth's 64bit injectso port☆74Updated 14 years ago
- Be able to execute memory snapshots so they can start running where they left off.☆35Updated 10 years ago
- Resources for reverse engineering Go binaries☆41Updated 10 years ago
- python library for dumping a linux process from memory☆34Updated 14 years ago
- A collection of shellcodes☆68Updated 12 years ago
- ELF binary infector☆32Updated 13 years ago
- collection of evil code☆14Updated 12 years ago
- A hypervisor or virtual machine monitor (VMM) fuzzer☆28Updated 5 years ago
- Linux kernel JIT spray for SMEP / KERNEXEC bypass☆55Updated 12 years ago
- A collection of tricky (and sometimes) funny shellcodes☆24Updated 13 years ago
- Proof Of Concept for inserting code in ELF binaries.☆26Updated 11 years ago
- Tool to view heap chunks and memory writes (using pintool)☆39Updated 6 years ago
- Writeup of the Oracle DSR stack buffer overflow vulnerability (DRA) CVE-2014-6598☆14Updated 10 years ago
- runtime code injector for Linux☆27Updated 13 years ago
- A library for efficient interception of established TCP connections☆19Updated 9 years ago
- Anti live forensic linux LKM rootkit☆17Updated 8 years ago
- This rearranges an ELF object file so it can be used as shellcode.☆42Updated 10 years ago
- iknowthis Linux SystemCall Fuzzer☆20Updated 5 years ago
- Diaphora, a Free and Open Source program diffing tool☆22Updated 5 years ago
- Basic x86 Symbolic Execution for educational purposes☆18Updated 7 years ago
- Script that dumps running process memory from Linux systems using /proc.☆79Updated 11 years ago
- PoC to append and extract data at the end of an ELF file☆20Updated 7 years ago
- A rootkit implemented as a linux kernel module☆17Updated 9 years ago
- Web based code browser using clang to provide basic code analysis.☆44Updated 7 years ago
- Draft of generic instrumentation tool based on QEMU using eBPF to implement trivial instrumentations with trivial code☆18Updated 5 years ago
- Quickly find references to the specified Immediate number, or find the function call of specifies offset, and generate C++ functions call…☆25Updated 8 years ago
- tracy - a system call tracer and injector. Find us in #tracy on irc.freenode.net☆72Updated 5 years ago
- A PoC implementation of the meltdown attack described in https://meltdownattack.com/meltdown.pdf☆135Updated 7 years ago
- ☆36Updated 12 years ago
- Test suite for bypassing Malware sandboxes.☆39Updated 10 years ago