nbulischeck / tyton
Kernel-Mode Rootkit Hunter
☆369Updated 3 years ago
Alternatives and similar repositories for tyton
Users that are interested in tyton are comparing it to the libraries listed below
Sorting:
- linux rootkit adapted for 2.6 and 3.x☆209Updated 9 years ago
- fireELF - Fileless Linux Malware Framework☆668Updated 6 years ago
- Linux ELF x32/x64 ASLR DEP/NX bypass exploit with stack-spraying☆301Updated 2 years ago
- HORSEPILL rootkit PoC☆228Updated 8 years ago
- linux rootkit☆159Updated 7 years ago
- LibZeroEvil & the Research Rootkit project.☆595Updated 3 years ago
- A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会☆165Updated 5 years ago
- The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samp…☆746Updated last year
- A POC for the Huge Dirty Cow vulnerability (CVE-2017-1000405)☆201Updated 7 years ago
- Linux Rootkit Scanner☆88Updated 3 years ago
- DrSemu - Sandboxed Malware Detection and Classification Tool Based on Dynamic Behavior☆272Updated 5 years ago
- The Multiplatform Linux Sandbox☆260Updated 3 years ago
- Public work for CVE-2019-0708☆292Updated 5 years ago
- UAC 0day, all day!☆278Updated 7 years ago
- Script to execute in memory a sequence of opcodes☆408Updated 10 years ago
- GhostTunnel is a covert backdoor transmission method that can be used in an isolated environment.☆329Updated 6 years ago
- Decept Network Protocol Proxy☆276Updated 2 years ago
- ☆234Updated 6 years ago
- An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits☆345Updated 4 years ago
- Linux LD_PRELOAD rootkit (x86 and x86_64 architectures)☆957Updated 4 years ago
- ☆469Updated 7 years ago
- ELF anti-forensics exec, for injecting full dynamic executables into process image (With thread injection)☆135Updated 7 years ago
- A LKM rootkit for most newer kernel versions.☆174Updated 7 years ago
- A PowerShell example of the Windows zero day priv esc☆326Updated 6 years ago
- Arbitrary code execution with kernel privileges using CVE-2018-8897.☆413Updated 6 years ago
- Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional feat…☆783Updated last year
- collection of verified Linux kernel exploits☆187Updated 4 years ago
- Proof-of-Concept exploits for CVE-2017-11882☆495Updated 7 years ago
- HTran is a connection bouncer, a kind of proxy server. A “listener” program is hacked stealthily onto an unsuspecting host anywhere on t…☆257Updated 4 years ago
- Tool written in python3 to determine where the AV signature is located in a binary/payload☆313Updated 7 years ago