vkobel / linux-syscall-hook-rootkitLinks
Simple kernel module that hooks the `execve` syscall and waits for `date` to be executed with the `backd00r` argument followed by a PID number, elevating it to root credentials.
☆25Updated 5 years ago
Alternatives and similar repositories for linux-syscall-hook-rootkit
Users that are interested in linux-syscall-hook-rootkit are comparing it to the libraries listed below
Sorting:
- A small library to modify all page-table levels of all processes from user space for x86_64 and ARMv8.☆277Updated 9 months ago
- An ongoing attempt to create own hypervisior from scratch in linux.☆51Updated 4 years ago
- Using ftrace for function hooking in Linux kernel☆294Updated 4 years ago
- Linux Kernel hooking engine (x86)☆385Updated 3 months ago
- Intel Vt-x/EPT based thin-hypervisor for windows with minimum possible code.☆182Updated 8 years ago
- ☆171Updated last year
- ☆21Updated 3 years ago
- Explore a live Linux kernel's memory using GDB☆117Updated 3 years ago
- A git clone of the official mercurial repository☆94Updated last week
- Kernel Address Space Layout Derandomization (KASLD) - A collection of various techniques to infer the Linux kernel base virtual address a…☆468Updated last year
- KVM-based Virtual Machine Introspection☆357Updated 3 months ago
- Examples for: Learning KVM - implement your own kernel☆380Updated 2 years ago
- ☆12Updated 3 years ago
- ☆62Updated 10 months ago
- A micro hypervisor for running micro VMs☆270Updated last year
- PCI device for qemu with mmio, pio, dma☆77Updated 9 years ago
- A custom ELF linker/loader for installing ET_REL binary patches at runtime☆186Updated last week
- 📡🐧 Linux kernel syscall implementation tracker☆267Updated 3 months ago
- Information about Linux system calls on different architectures☆173Updated last month
- Breaking Confidential VMs with Malicious Interrupts (USENIX Security 2024)☆34Updated last year
- Simple AMD-V (SVM) Virtualization Extensions Demo☆20Updated 8 years ago
- A network interface for GDB for Linux Kernel☆73Updated 5 months ago
- 👓A collection of papers/tools/exploits for UEFI security.☆205Updated 4 months ago
- small elf loader☆174Updated last year
- ☆93Updated last year
- Collection of Spectre-type, Meltdown-type and MDS-type PoCs☆10Updated 5 years ago
- A bare minimum hypervisor on AMD and Intel processors for learners.☆331Updated 4 months ago
- A tiny debugger implement the GDB Remote Serial Protocol. Can work on i386, x86_64, ARM and PowerPC.☆176Updated 3 years ago
- A tool to sample a QEMU-KVM's memory access pattern at page level based on Intel VT-x☆23Updated 6 years ago
- Proof-of-concept implementation for the paper "CacheWarp: Software-based Fault Injection using Selective State Reset" (USENIX Security 20…☆65Updated last year