thalium / rkchkLinks
Rust Linux Kernel Module designed for LKM rootkit detection
☆50Updated 4 months ago
Alternatives and similar repositories for rkchk
Users that are interested in rkchk are comparing it to the libraries listed below
Sorting:
- Linpmem is a linux memory acquisition tool☆85Updated 3 weeks ago
- Cheat sheet to detect and remove linux kernel rootkit☆67Updated 6 months ago
- ☆67Updated 7 months ago
- Userland exec PoC to be used as attack vector technique☆85Updated 5 months ago
- Open Source eBPF Malware Analysis Framework☆48Updated 8 months ago
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆64Updated 2 months ago
- Attacking the cleanup_module function of a kernel module☆36Updated 2 weeks ago
- kubernetes rootkit☆31Updated last year
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆115Updated 3 months ago
- eBPF Memory Dump Tool☆78Updated 3 weeks ago
- OffensiveCon 2024 Repo, contains PoCs and materials for talk "UEFI and the Task of the Translator"☆42Updated last year
- CVE-2024-30090 - LPE PoC☆107Updated 8 months ago
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆119Updated last month
- POC of GITHUB simple C2 in rust☆53Updated 5 months ago
- A C++ tool for process memory scanning & suspicious telemetry generation that attempts to detect a number of malicious techniques used by…☆83Updated last year
- Retrieve inner payloads from Donut samples☆100Updated last year
- ☆52Updated 8 months ago
- A simple Meterpreter stager written in Rust.☆38Updated 9 months ago
- Collection of codes focused on Linux rootkits☆132Updated 3 weeks ago
- Payload encoding utility to effectively lower payload entropy.☆118Updated 2 months ago
- Monarch - The Adversary Emulation Toolkit☆61Updated 6 months ago
- Select any exported function in a dll as the new dll's entry point.☆81Updated 8 months ago
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆100Updated last year
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆96Updated this week
- Linux rootkit for educational purposes☆32Updated last year
- bootloaders.io is a curated list of known malicious bootloaders for various operating systems. The project aims to assist security profes…☆62Updated last year
- ☆102Updated 7 months ago
- Make an Linux Kernel rootkit visible again.☆53Updated 4 months ago
- ☆59Updated last year
- A remote process injection using process snapshotting based on https://gitlab.com/ORCA000/snaploader , in rust. It creates a sacrificial …☆49Updated 5 months ago