rootfoo / rootkitLinks
Fully functional but simplified Linux Kernel Module (LKM) Rootkit for educational purposes
☆62Updated 6 years ago
Alternatives and similar repositories for rootkit
Users that are interested in rootkit are comparing it to the libraries listed below
Sorting:
- JynxKit2 is an LD_PRELOAD userland rootkit based on the original JynxKit. The backdoor has been replaced with an "accept()" system hook.☆179Updated 12 years ago
- A LKM rootkit for most newer kernel versions.☆178Updated 8 years ago
- LKM rootkit for Linux x86 with the 2.6 kernel. It inserts salts inside system_call and sysenter_entry.☆87Updated 2 years ago
- Proof of concept for injecting simple shellcode via ptrace into a running process.☆72Updated 2 years ago
- The first Linux hooking framework to allow merging two binary files into one!☆96Updated 4 months ago
- Injects code into ELF executables post-build☆236Updated last year
- This is a kernel module invoked reverse shell proof of concept.☆72Updated 5 years ago
- A ptrace POC by hooking SSH to reveal provided passwords☆187Updated 8 years ago
- Linux v4.x.x Rootkit☆93Updated last year
- ELF anti-forensics exec, for injecting full dynamic executables into process image (With thread injection)☆138Updated 7 years ago
- ELF launcher for encrypted binaries decrypted on-the-fly and executed in memory☆26Updated 5 years ago
- a summary of linux rootkits published on GitHub☆181Updated 5 years ago
- Matryoshka - stacked LKM loader☆53Updated 2 years ago
- Reverse engineering challenges☆52Updated 5 years ago
- ELF Shared library injector using DT_NEEDED precedence infection. Acts as a permanent LD_PRELOAD☆111Updated 5 years ago
- assembly language examples, mostly Linux☆44Updated 4 years ago
- sample linux x86_64 ELF virus☆53Updated 7 years ago
- Hardcore corruption of my execve() vulnerability in WSL☆215Updated 7 years ago
- Linux Rootkits (4.x Kernel)☆86Updated 4 years ago
- A simple embedded Linux backdoor.☆199Updated 4 years ago
- Linux 4.9 Loadable Kernel Module to hide processes from system utilities☆67Updated 7 years ago
- A tool like /bin/ps but uses /proc/kcore for walking the tasklist; this finds hidden processes☆58Updated 10 years ago
- Code for my 0x00sec.org posts☆327Updated 5 years ago
- Devestating and awesome Linux X86_64 ELF Virus☆232Updated 3 years ago
- Backdoor that listens for specially crafted ICMP packets and spawns reverse shells.☆72Updated 5 years ago
- Collection of shellcodes that use a variety of syscalls in order to bypass some seccomp configurations☆70Updated 8 years ago
- LKRG bypass methods☆73Updated 5 years ago
- Rootkit spotter - experimental Linux rootkit finder LKM☆30Updated 5 years ago
- Hide processes as a normal user in Linux.☆258Updated last year
- Alphanumeric Shellcode (x86) Encoder☆75Updated 3 years ago