vkobel / linux-syscall-hook-rootkit

Simple kernel module that hooks the `execve` syscall and waits for `date` to be executed with the `backd00r` argument followed by a PID number, elevating it to root credentials.
17Updated 4 years ago

Related projects: