theSecHunter / Hades-LinuxLinks
Hades is a Host-Based Intrusion Detection System based on both eBPF(kernel) and netlink/cn_proc(userspace).
☆25Updated 9 months ago
Alternatives and similar repositories for Hades-Linux
Users that are interested in Hades-Linux are comparing it to the libraries listed below
Sorting:
- 沙箱测试,测评国内常见沙箱的代码与结论☆103Updated 4 years ago
- 一款linux下的安全产品目的是满足个人安全需求有SSH爆破防护和SYN攻击扫描防护功能,基于netfilter,☆19Updated last year
- 简单安排一下 autochk.sys 这个rootkit☆73Updated 2 years ago
- ☆37Updated 5 years ago
- Windows Defender VDM lua collections☆47Updated 2 years ago
- 40行代码检测到大部分CobaltStrike的shellcode☆290Updated 4 years ago
- CobaltStrikeDetect☆49Updated 2 months ago
- SysEye是一个window上的基于att&ck现代EDR设计思想的威胁响应工具.有效检测常见的未知威胁与已知威胁.防守方的利剑☆63Updated 3 years ago
- Windows CVE主防(HIPS/HIDS)☆56Updated 4 years ago
- IDA Python script for generating Windows x86 shellcode with one click☆38Updated 2 years ago
- windwos内核研究与驱动Code☆66Updated 3 years ago
- 大数字驱动逆向代码☆74Updated last year
- Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&☆57Updated 2 months ago
- ☆91Updated 4 years ago
- 模仿操作系统,加载pe文件到内存中☆75Updated 6 years ago
- 复现《EDR的梦魇:Storm-0978使用新型内核注入技术“Step Bear”》☆138Updated 10 months ago
- about how to make a anti-virus engine☆86Updated 3 months ago
- ☆21Updated 5 years ago
- Beacon compiled using clang☆72Updated 2 years ago
- [windows]pe -> shellcode -> shellcodeLoader -> (pe2shellcode go on?)☆78Updated 3 years ago
- 白文件扫描器 非公开☆28Updated 4 years ago
- ☆68Updated last year
- UAC_wenpon☆49Updated 3 years ago
- WINDOWS黑客編程技術詳解 [Windows-Hack-Programming backup]☆46Updated 6 years ago
- Remote Download and Memory Execute for shellcode framework☆93Updated 2 years ago
- 笔者的在原作者池风水利用工具(以下简称工具)基础上进行二次开发,新增了全自动获取内核调试模块符号的偏移量及配置参数和不同漏洞利用方式优化等功能, 解决了不同Windows版本适配问题,工具包括适配驱动和利用程序两部分组成,实现了在Windows 10 19H1之后任意版本包…☆76Updated 3 years ago
- 过去写的一些Windows安全研究相关代码☆136Updated 6 years ago
- 利用图片隐写术来远程动态加载shellcode☆97Updated 2 years ago
- power-kill is a project that kill protected processes (such as EDR or AV) by injecting shellcode into high privilege processes☆48Updated 3 years ago
- 通杀检测基于白文 件patch黑代码的免杀技术的后门☆174Updated last year