All Projects → milabs → Awesome Linux Rootkits

milabs / Awesome Linux Rootkits

Licence: cc0-1.0
awesome-linux-rootkits

Projects that are alternatives of or similar to Awesome Linux Rootkits

Diamorphine
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64)
Stars: ✭ 725 (+24.36%)
Mutual labels:  linux-kernel, rootkit
ebpfkit
ebpfkit is a rootkit powered by eBPF
Stars: ✭ 472 (-19.04%)
Mutual labels:  rootkit, linux-kernel
Sutekh
An example rootkit that gives a userland process root permissions
Stars: ✭ 62 (-89.37%)
Mutual labels:  linux-kernel, rootkit
ebpfkit-monitor
ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits
Stars: ✭ 80 (-86.28%)
Mutual labels:  rootkit, linux-kernel
Umbra
A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.
Stars: ✭ 98 (-83.19%)
Mutual labels:  rootkit, linux-kernel
satan
🔓 x86 Linux Kernel rootkit for Debian 9 (4.9.0-11-686-pae)
Stars: ✭ 31 (-94.68%)
Mutual labels:  rootkit, linux-kernel
Linux kernel cves
Tracking CVEs for the linux Kernel
Stars: ✭ 357 (-38.77%)
Mutual labels:  linux-kernel
Awesome Android Performance
🏆Explore Android performance optimization in depth(continuous updating ...)
Stars: ✭ 433 (-25.73%)
Mutual labels:  linux-kernel
Hideprocess
A basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager
Stars: ✭ 329 (-43.57%)
Mutual labels:  rootkit
Linux
XanMod: Linux kernel source code tree
Stars: ✭ 310 (-46.83%)
Mutual labels:  linux-kernel
Linuxboot
The LinuxBoot project is working to enable Linux to replace your firmware on all platforms.
Stars: ✭ 554 (-4.97%)
Mutual labels:  linux-kernel
Rdma Core
RDMA core userspace libraries and daemons
Stars: ✭ 536 (-8.06%)
Mutual labels:  linux-kernel
Emp3r0r
linux post-exploitation framework made by linux user
Stars: ✭ 419 (-28.13%)
Mutual labels:  rootkit
Ldt
Linux Driver Template
Stars: ✭ 363 (-37.74%)
Mutual labels:  linux-kernel
Hvmi
Hypervisor Memory Introspection Core Library
Stars: ✭ 438 (-24.87%)
Mutual labels:  rootkit
Linux Kernel Exploitation
A collection of links related to Linux kernel security and exploitation
Stars: ✭ 3,859 (+561.92%)
Mutual labels:  linux-kernel
Spy
👀 Linux kernel mode debugfs keylogger
Stars: ✭ 546 (-6.35%)
Mutual labels:  linux-kernel
Vmlinux To Elf
A tool to recover a fully analyzable .ELF from a raw kernel, through extracting the kernel symbol table (kallsyms)
Stars: ✭ 317 (-45.63%)
Mutual labels:  linux-kernel
Dattobd
kernel module for taking block-level snapshots and incremental backups of Linux block devices
Stars: ✭ 400 (-31.39%)
Mutual labels:  linux-kernel
Linux0.11
Linux内核0.11完全注释V3.0配套源代码
Stars: ✭ 497 (-14.75%)
Mutual labels:  linux-kernel

awesome-linux-rootkits Awesome

🔑 feature table

Environment:

  • CPU architecture
  • Kernel/User mode (or mixed)

Core capabilities:

  • Persistency
  • Management interface
  • Altering system (library) behavior

Stealth capabilities:

  • Detection evasion
  • System logs cleaning (filtering)

Hiding stuff capabilities:

  • Hiding of files and directories
  • Hiding (tampering) of file contents
  • Hiding of processes and process trees
  • Hiding of network connections and activity
  • Hiding of process accounting information (like CPU usage)

Additional functions:

  • Keylogger
  • Backdoor/shell
  • Gaining priveleges

🙈 user mode rootkits

🙉 kernel mode rootkits

🙊 related stuff

Contributing

Please refer the guidelines at contributing.md for details

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].