vkobel / linux-syscall-hook-rootkit
Simple kernel module that hooks the `execve` syscall and waits for `date` to be executed with the `backd00r` argument followed by a PID number, elevating it to root credentials.
☆23Updated 4 years ago
Alternatives and similar repositories for linux-syscall-hook-rootkit:
Users that are interested in linux-syscall-hook-rootkit are comparing it to the libraries listed below
- A small library to modify all page-table levels of all processes from user space for x86_64 and ARMv8.☆249Updated 4 months ago
- ☆90Updated 11 months ago
- Explore a live Linux kernel's memory using GDB☆114Updated 2 years ago
- A git clone of the official mercurial repository☆89Updated 3 months ago
- Linux Kernel hooking engine (x86)☆338Updated 3 months ago
- ☆154Updated 2 months ago
- An ongoing attempt to create own hypervisior from scratch in linux.☆49Updated 3 years ago
- A very simple hypervisor for learning experience.☆136Updated 3 years ago
- 64bit bare metal hypervisor built from scratch with Intel VT-x☆91Updated 4 years ago
- EFI Byte Code Virtual Machine in userspace☆77Updated 2 years ago
- A network interface for GDB for Linux Kernel☆66Updated last year
- Collection of simple anti-debugging tricks for Linux☆55Updated 6 years ago
- A collection of Linux kernel modules for educational purposes☆40Updated 8 years ago
- The runtime DXE driver monitoring access to the UEFI variables by hooking the runtime service table.☆138Updated 4 years ago
- userland exec for Linux x86_64☆66Updated 2 years ago
- Helper script for Linux kernel disassemble or debugging with IDA Pro on VMware + GDB stub (including some symbols helpers)☆36Updated last year
- The sample DXE runtime driver demonstrating how to program DMA remapping.☆58Updated last year
- ugly code to check linux kernel memory and dump some internal structures☆46Updated 4 months ago
- A small kernel module that can hook arbitrary syscalls on x86_64☆52Updated 5 years ago
- Intel ATR Training: Security of BIOS/UEFI System Firmware from Attacker and Defender Perspectives☆96Updated 7 years ago
- Kernel programming: This is a simple kernel module implementation for enforcing access control policies using Linux Security Module frame…☆31Updated 6 years ago
- ☆19Updated 2 years ago
- Kernel Address Space Layout Derandomization (KASLD) - A collection of various techniques to infer the Linux kernel base virtual address a…☆436Updated 11 months ago
- Collection of Linux Kernel Modules and PoC to discover, learn and practice Linux Kernel Development☆51Updated 4 years ago
- Intel Vt-x/EPT based thin-hypervisor for windows with minimum possible code.☆174Updated 7 years ago
- Fork of KVM with Virtual Machine Introspection patches☆36Updated last year
- A simple kernel written in Rust for studying purposes.☆51Updated 6 years ago
- Control-Flow Integrity implementation for the Linux Kernel 3.19☆20Updated 5 years ago
- HardsHeap: A Universal and Extensible Framework for Evaluating Secure Allocators☆34Updated 3 years ago
- ☆53Updated 3 weeks ago