niv256 / simple_rootkitLinks
A simple LKM kernel space rootkit for v5.x linux with multiple functions.
☆10Updated 5 years ago
Alternatives and similar repositories for simple_rootkit
Users that are interested in simple_rootkit are comparing it to the libraries listed below
Sorting:
- Yet another windows internals repo☆210Updated 4 years ago
- ☆108Updated 6 years ago
- Set of antianalysis techniques found in malware☆133Updated 2 years ago
- My repository to upload drivers from different books and all the information related to windows internals.☆163Updated 6 years ago
- Parsers for custom malware formats ("Funky malware formats")☆98Updated 4 years ago
- Kernel Exploits☆259Updated 4 years ago
- Exploit Development - Weaponized Exploit and Proof of Concepts (PoC)☆235Updated 2 years ago
- CFB is a ProcMon-style tool designed to assist capturing IRPs sent to Windows drivers.☆333Updated last year
- This is a place to share my miscellaneous projects.☆116Updated 5 years ago
- Do you want to use x64dbg instead of immunity debugger? oscp eCPPTv2 buffer overflow exploits pocs☆90Updated last year
- Anti-reverse Compilation☆34Updated 4 years ago
- ☆165Updated 4 years ago
- Windows Kernel Programming☆133Updated 5 years ago
- Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CV…☆256Updated 3 years ago
- ☆199Updated 8 years ago
- ☆12Updated 4 years ago
- Driver Initial Reconnaissance Tool☆125Updated 6 years ago
- This project provides a collection of Microsoft Windows kernel structures, unions and enumerations. Most of them are not officially docum…☆231Updated 2 months ago
- BluePill: Neutralizing Anti-Analysis Behavior in Malware Dissection (Black Hat Europe 2019, IEEE TIFS 2020)☆128Updated 4 years ago
- WIP Emotet Control Flow Unflattening using miasm and radare2☆23Updated 3 years ago
- Simple 32/64-bit PEs loader.☆138Updated 7 years ago
- ☆129Updated 5 years ago
- RIXED LABS is open for contributions for it's community papers . If you want to publish a blog or a paper , it will be added to the site…☆80Updated 3 years ago
- A kernel rootkit with remote command and control interface for windows☆109Updated 7 years ago
- Automatically rebuild Import Address Table for dumped PE file. With python bindings!☆121Updated 6 years ago
- My notes while studying Windows internals☆443Updated last year
- PoC exploiting Aligned Chunk Confusion on Windows kernel Segment Heap☆213Updated 5 years ago
- A virtualization-based endpoint security solution for Windows☆88Updated 4 years ago
- Malware dynamic instrumentation tool based on frida framework☆110Updated 5 years ago
- Zerokit/GAPZ rootkit (non buildable and only for researching)☆185Updated 6 years ago