milabs / kmatryoshka
Matryoshka - stacked LKM loader
☆50Updated last year
Alternatives and similar repositories for kmatryoshka:
Users that are interested in kmatryoshka are comparing it to the libraries listed below
- LKM rootkit for Linux x86 with the 2.6 kernel. It inserts salts inside system_call and sysenter_entry.☆84Updated last year
- Linux Kernel module-less implant (backdoor)☆69Updated 3 years ago
- A simple tool to view important DLL Characteristics and change DEP and ASLR☆44Updated 6 years ago
- Exploits pack for the Windows Kernel mode driver HackSysExtremeVulnerableDriver written for educational purposes.☆65Updated 3 years ago
- Reflective SO injection is a library injection technique in which the concept of reflective programming is employed to perform the loadin…☆115Updated 8 years ago
- x86_64 linux rootkit using debug registers☆52Updated 3 years ago
- Master list of all my vulnerability discoveries. Mostly 3rd party kernel drivers.☆48Updated 4 years ago
- Ebfuscator: Abusing system errors for binary obfuscation☆52Updated 4 years ago
- Code for diskless loading of ELF Shared Library using Reflective DLL Injection☆55Updated 8 years ago
- Tools for instrumenting Windows Defender's mpengine.dll☆36Updated 6 years ago
- Process reimaging proof of concept code☆95Updated 5 years ago
- Rootkit spotter - experimental Linux rootkit finder LKM☆27Updated 4 years ago
- ☆51Updated 7 years ago
- Sandbox escape using WinHTTP Web Proxy Auto-Discovery Service☆85Updated 5 years ago
- NASM Linux x86_64 pure (no deps) shared library (.so), POC for Reflective ELF SO injection☆30Updated last year
- FLARE Kernel Shellcode Loader☆176Updated 5 years ago
- In line function hooking LKM rootkit☆51Updated 4 years ago
- ☆15Updated 6 years ago
- ☆33Updated 8 years ago
- ☆48Updated 4 years ago
- Public documents related to my talk "Bypass Windows Exploit Guard ASR" at Offensive Con 2019.☆93Updated 5 years ago
- GUI Application in C# to run and disassemble shellcode☆35Updated 7 years ago
- ☆86Updated 4 months ago
- ☆49Updated 5 years ago
- Proxy system calls over an RPC channel☆97Updated 2 years ago
- Helper idapython code for reversing kmdf drivers☆72Updated 2 years ago
- ☆100Updated 6 years ago
- ☆27Updated 5 years ago
- Poc for ELF64 runtime infection via GOT poisoning technique by elfmaster☆29Updated 4 years ago
- #INFILTRATE20 raptor's party pack.☆28Updated last year