sysprog21 / lkm-hidden
A Linux kernel module which hides itself
☆41Updated 3 years ago
Alternatives and similar repositories for lkm-hidden:
Users that are interested in lkm-hidden are comparing it to the libraries listed below
- In-memory ELF shared library loading☆37Updated 2 years ago
- system call hooking on arm64 linux via a variety of methods☆47Updated 2 years ago
- Run some secret code invisible from debugger single step.(x86 process on x64 windows only)☆24Updated 4 years ago
- PoC for obfuscating the dynamic symbol table injecting a custom Hash Table to do symbol resolution☆27Updated 4 years ago
- ELF static analysis and injection framework that parse, manipulate, patch and camouflage ELF files.☆57Updated last week
- Dectect syscall hooking using eBPF☆143Updated last year
- Simple library to Read and Write Memory of a Linux Process through custom Kernel Module☆48Updated 4 years ago
- Injecting into SELinux-protected system service processes under root on Android.☆38Updated 11 months ago
- An IDA processor for eBPF bytecode☆62Updated 2 months ago
- Implementation of sllvm obfuscator☆66Updated 2 years ago
- An IDA processor for eBPF bytecode☆47Updated 3 years ago
- 关于intel和amd指令行为不一样这件事☆60Updated 2 years ago
- Bootkits☆19Updated last year
- ☆19Updated 7 years ago
- ETrace is a syscall tracing utility powered by eBPF☆24Updated last year
- Tools for Linux kernel debugging on Bochs (including symbols, native Bochs debugger and IDA PRO)☆31Updated last year
- Example of an ELF parser to learn about the ELF format☆10Updated 3 months ago
- Dice CTF 2022 breach write-up☆15Updated 2 years ago
- Triton based symbolic emulator☆16Updated 2 years ago
- Toy LLVM obfuscator pass☆71Updated 3 years ago
- Change vermagic and CRCs of a Linux Kernel Module☆51Updated 6 years ago
- Helper script for Linux kernel disassemble or debugging with IDA Pro on VMware + GDB stub (including some symbols helpers)☆36Updated last year
- A simple anti-rootkit Linux kernel module for an 'Operating Systems Security' course.☆15Updated 3 years ago
- A VMBR (Virtual-Machine Based Rootkit) which runs a guest OS and sends the attacker its data☆27Updated 9 months ago
- Intel Hardware Trace Library☆66Updated 4 months ago
- IDA SIG files for multiarch uClibc library☆38Updated 6 years ago
- Frida's setHardwareWatchpoint tutorial☆25Updated 3 months ago
- load so file into current memory space and run function☆102Updated 7 years ago
- 跨平台模拟执行unicorn框架基于Qemu的TCG模式(Tiny Code Generator),以无硬件虚拟化支持方式实现全系统的虚拟化,支持跨平台和架构的CPU指令模拟,本文讨论是一款笔者的实验性项目采用Windows Hypervisor Platform虚拟机模式…☆65Updated last year
- The tool can be used to eliminate redundant instructions in a basic block.☆79Updated last year