thalium / rkchkLinks
Rust Linux Kernel Module designed for LKM rootkit detection
☆58Updated 10 months ago
Alternatives and similar repositories for rkchk
Users that are interested in rkchk are comparing it to the libraries listed below
Sorting:
- Userland exec PoC to be used as attack vector technique☆94Updated 3 months ago
- Linpmem is a linux memory acquisition tool☆95Updated 7 months ago
- Attacking the cleanup_module function of a kernel module☆55Updated 7 months ago
- Open Source eBPF Malware Analysis Framework☆54Updated last year
- A tool to interact with Windows drivers to perform a raw disk read and parse out target files without calling standard Windows file APIs☆104Updated 5 months ago
- Circumventing "noexec" mount flag to execute arbitrary linux binaries by ptrace-less process injection☆136Updated 8 months ago
- ElfDoor-gcc is an LD_PRELOAD that hijacks gcc to inject malicious code into binaries during linking, without touching the source code.☆131Updated 9 months ago
- Cheat sheet to detect and remove linux kernel rootkit☆78Updated last year
- A C++ tool for process memory scanning & suspicious telemetry generation that attempts to detect a number of malicious techniques used by…☆85Updated last year
- Comprehensive Windows Syscall Extraction & Analysis Framework☆160Updated 5 months ago
- Payload encoding utility to effectively lower payload entropy.☆123Updated 9 months ago
- ☆91Updated last year
- kubernetes rootkit☆34Updated 2 years ago
- OffensiveCon 2024 Repo, contains PoCs and materials for talk "UEFI and the Task of the Translator"☆43Updated last year
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆79Updated last week
- CVE-2024-30090 - LPE PoC☆108Updated last year
- A set of rootkit-like abilities for unprivileged users, and vulnerabilities based on the DOT-to-NT path conversion known issue☆107Updated last year
- eBPF Memory Dump Tool☆98Updated 5 months ago
- Vibe Malware Triage - MCP server for static PE analysis.☆74Updated 2 months ago
- Windows AppLocker Driver (appid.sys) LPE☆72Updated last year
- Select any exported function in a dll as the new dll's entry point.☆82Updated last year
- A Linux kernel rootkit in Rust using a custom made type-2 hypervisor, eBPF XDP and TC programs☆335Updated 7 months ago
- POC of GITHUB simple C2 in rust☆52Updated 6 months ago
- ☆105Updated last year
- Collection of codes focused on Linux rootkits☆195Updated 3 months ago
- Monarch - The Adversary Emulation Toolkit☆63Updated last year
- Rust malware EDR evasion via direct syscalls, fully implemented as an example in Rust☆82Updated last year
- ☆52Updated 10 months ago
- Repository for the DEF CON 33 talk: Kill Chain Reloaded☆77Updated 6 months ago
- HEVD Exploit: BufferOverflowNonPagedPoolNx on Windows 10 22H2 - Escalating from Low Integrity to SYSTEM via Aligned Chunk Confusion☆65Updated 9 months ago