All Categories → Security → rootkit

Top 45 rootkit open source projects

Bdvl
LD_PRELOAD Linux rootkit (x86 & ARM)
Openssh Backdoor Kit
💣 just for fun ¯\_(ツ)_/¯
Php Backdoor
Your interpreter isn’t safe anymore  —  The PHP module backdoor
✭ 211
crootkit
Hiddenwall
Tool to generate a Linux kernel module for custom rules with Netfilter hooking. (block ports, Hidden mode, functions to protect etc)
Shadow Box For X86
Shadow-Box: Lightweight and Practical Kernel Protector for x86 (Presented at BlackHat Asia 2017/2018, beVX 2018 and HITBSecConf 2017)
Android Rootkit
A rootkit for Android. Based on "Android platform based linux kernel rootkit" from Phrack Issue 68
Malware
Rootkits | Backdoors | Sniffers | Virus | Ransomware | Steganography | Cryptography | Shellcodes | Webshells | Keylogger | Botnets | Worms | Other Network Tools
Www.rootkit.com
www.rootkit.com users section mirror, sql database dump, and a few other files/rootkits.
Awesome Linux Rootkits
a summary of linux rootkits published on GitHub
Spacecow
Windows Rootkit written in Python
Shadow Box For Arm
Shadow-Box: Lightweight and Practical Kernel Protector for ARM (Presented at BlackHat Asia 2018)
Sutekh
An example rootkit that gives a userland process root permissions
Webshell
Webshell && Backdoor Collection
Rootkits List Download
This is the list of all rootkits found so far on github and other sites.
Vlany
Linux LD_PRELOAD rootkit (x86 and x86_64 architectures)
Hidden
Windows driver with usermode interface which can hide objects of file-system and registry, protect processes and etc
Rootkit
Linux rootkit for Ubuntu 16.04 and 10.04 (Linux Kernels 4.4.0 and 2.6.32), both i386 and amd64
✭ 601
crootkit
Vegile
This tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process,unlimited your session in metasploit and transparent. Even when it killed, it will re-run again. There always be a procces which while run another process,So we can assume that this procces is unstopable like a Ghost in The Shell
Hvmi
Hypervisor Memory Introspection Core Library
Emp3r0r
linux post-exploitation framework made by linux user
Hideprocess
A basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager
✭ 329
crootkit
S6 pcie microblaze
PCI Express DIY hacking toolkit for Xilinx SP605
superhide
Example of hooking a linux systemcall
raisin
Reverse shell and rootkit
SMM-Rootkit
SMM rootkit similar to LoJax or MosaicRegressor
NtSymbol
Resolve DOS MZ executable symbols at runtime
Solaris
A local LKM rootkit loader/dropper that lists available security mechanisms
satan
🔓 x86 Linux Kernel rootkit for Debian 9 (4.9.0-11-686-pae)
Vegile
This tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process,unlimited your session in metasploit and transparent. Even when it killed, it will re-run again. There always be a procces which while run another process,So we can assume that this procces is unstopable like a Ghost in The Shell
HideProcessHookMDL
A simple rootkit to hide a process
ebpfkit-monitor
ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits
Simple-Antirootkit-SST-Unhooker
This is a demo project to illustrate the way to verify and restore original SST in case of some malware hooks
Umbra
A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.
1-45 of 45 rootkit projects