thalium / rkchkLinks
Rust Linux Kernel Module designed for LKM rootkit detection
☆53Updated 8 months ago
Alternatives and similar repositories for rkchk
Users that are interested in rkchk are comparing it to the libraries listed below
Sorting:
- Linpmem is a linux memory acquisition tool☆94Updated 4 months ago
- Userland exec PoC to be used as attack vector technique☆94Updated 3 weeks ago
- Open Source eBPF Malware Analysis Framework☆53Updated last year
- Attacking the cleanup_module function of a kernel module☆52Updated 4 months ago
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆73Updated 2 months ago
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆135Updated 5 months ago
- A C++ tool for process memory scanning & suspicious telemetry generation that attempts to detect a number of malicious techniques used by…☆83Updated last year
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆130Updated 7 months ago
- Cheat sheet to detect and remove linux kernel rootkit☆74Updated 10 months ago
- Comprehensive Windows Syscall Extraction & Analysis Framework☆150Updated 2 months ago
- OffensiveCon 2024 Repo, contains PoCs and materials for talk "UEFI and the Task of the Translator"☆43Updated last year
- Payload encoding utility to effectively lower payload entropy.☆120Updated 7 months ago
- eBPF Memory Dump Tool☆90Updated 2 months ago
- A tool to interact with Windows drivers to perform a raw disk read and parse out target files without calling standard Windows file APIs☆96Updated 2 months ago
- ☆54Updated last year
- kubernetes rootkit☆35Updated last year
- ☆78Updated 11 months ago
- Collection of codes focused on Linux rootkits☆183Updated 3 weeks ago
- A simple Meterpreter stager written in Rust.☆42Updated last week
- A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs☆331Updated 4 months ago
- Convert Microsoft Defender Antivirus Signatures (VDM) into YARA rules☆132Updated last week
- Memory Obfuscation in Rust☆258Updated last week
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆105Updated last year
- eBPF hacks☆188Updated 11 months ago
- An automation plugin for Tiny-Tracer framework to trace and watch functions directly out of the executable's import table or trace logs (…☆120Updated last year
- Vibe Malware Triage - MCP server for static PE analysis.☆72Updated 5 months ago
- bootloaders.io is a curated list of known malicious bootloaders for various operating systems. The project aims to assist security profes…☆67Updated 2 years ago
- CVE-2024-30090 - LPE PoC☆108Updated last year
- ☆109Updated 11 months ago
- Aplos an extremely simple fuzzer for Windows binaries.☆68Updated 8 months ago