Open Source eBPF Malware Analysis Framework
☆54Oct 20, 2024Updated last year
Alternatives and similar repositories for Kairos
Users that are interested in Kairos are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Example of an ELF parser to learn about the ELF format☆11Oct 6, 2024Updated last year
- RE for champions☆15Updated this week
- Sample/PoC Windows kernel driver for detect DMA devices by using Vendor ID and Device ID signatures☆39Sep 22, 2024Updated last year
- POC for CVE-2023-29360☆12Aug 31, 2024Updated last year
- Windows Minidump loader for Ghidra☆29Sep 30, 2022Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆36Jan 23, 2025Updated last year
- LLVM Graph View for VSCode☆42Mar 25, 2025Updated last year
- Retrieve LAPS passwords from a domain. The tools is inspired in pyLAPS.☆32Mar 8, 2025Updated last year
- A simple UEFI bootkit made by @NSG650 and me.☆26Dec 29, 2024Updated last year
- Lightweight PDB symbol parser and resolver☆30Oct 28, 2024Updated last year
- PEIM (UEFI) bootkit targeting OVMF (EDK2)☆40Nov 28, 2023Updated 2 years ago
- ☆16Jul 17, 2024Updated last year
- LLVM-based ROP obfuscated compiler☆12Mar 24, 2022Updated 4 years ago
- Getting Started with eBPF☆27Nov 4, 2023Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Easily search LLVM headers for all major versions!☆19Sep 14, 2025Updated 7 months ago
- PDB Rewriting Rust Library☆29Apr 26, 2024Updated 2 years ago
- Utility library to display license notices☆12Apr 16, 2026Updated 2 weeks ago
- NailaoLoader: Hiding Execution Flow via Patching☆23Feb 27, 2025Updated last year
- ☆10Jul 1, 2023Updated 2 years ago
- Python bindings for the Icicle emulator.☆41Nov 6, 2025Updated 5 months ago
- POC about how to detect windows kernel debug by pool tag.☆13Nov 29, 2023Updated 2 years ago
- tvisor is a tiny 100% userspace syscall interception framework☆46Apr 13, 2024Updated 2 years ago
- ☆16Jan 23, 2022Updated 4 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Detection of rootkit file hiding activities through analysis of shifts in kernel function execution times.☆29Sep 10, 2025Updated 7 months ago
- PoCs for Kernelmode rootkit techniques research.☆436Mar 25, 2026Updated last month
- SECurityTr8Ker monitors the SEC's RSS feed for 8-K filings with cybersecurity incident disclosures.☆89Jun 20, 2025Updated 10 months ago
- Rule Engine for Dynamic Malware Analysis and Research☆25Apr 16, 2025Updated last year
- OpenHashAPI provides a secure method of communicating hashes and enables lightweight workflows for security practitioners and enthusiasts…☆13Oct 27, 2024Updated last year
- ☆12Jun 22, 2022Updated 3 years ago
- A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs☆341Feb 27, 2026Updated 2 months ago
- Nuke It From Orbit - remove AV/EDR with physical access☆274Dec 8, 2024Updated last year
- Proof Of Concepts☆56Jan 4, 2026Updated 4 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- ☆20Jul 11, 2021Updated 4 years ago
- Small micro-coded RISC-V softcore☆15Nov 27, 2018Updated 7 years ago
- SLOT: SMT-LLVM Optimizing Translation☆62Apr 17, 2025Updated last year
- Windows kernel debugger for Linux hosts running Windows under KVM/QEMU☆139Apr 18, 2026Updated 2 weeks ago
- Self-hosting binary instrumentation framework for security research☆12Apr 10, 2023Updated 3 years ago
- Detect WFP filters blocking EDR communications☆97Jan 5, 2024Updated 2 years ago
- The tool that bypasses the firewall's Application Based Rules and lets you connect to anywhere, ANY IP, ANY PORT and ANY APPLICATION.☆62Aug 19, 2024Updated last year