ebpfkit-monitorebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits
Stars: ✭ 80 (+86.05%)
ebpfkitebpfkit is a rootkit powered by eBPF
Stars: ✭ 472 (+997.67%)
Simple-Antirootkit-SST-UnhookerThis is a demo project to illustrate the way to verify and restore original SST in case of some malware hooks
Stars: ✭ 31 (-27.91%)
rkduckLinux v4.x.x Rootkit
Stars: ✭ 83 (+93.02%)
UmbraA LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.
Stars: ✭ 98 (+127.91%)
BdvlLD_PRELOAD Linux rootkit (x86 & ARM)
Stars: ✭ 232 (+439.53%)
Php BackdoorYour interpreter isn’t safe anymore — The PHP module backdoor
Stars: ✭ 211 (+390.7%)
HiddenwallTool to generate a Linux kernel module for custom rules with Netfilter hooking. (block ports, Hidden mode, functions to protect etc)
Stars: ✭ 187 (+334.88%)
Shadow Box For X86Shadow-Box: Lightweight and Practical Kernel Protector for x86 (Presented at BlackHat Asia 2017/2018, beVX 2018 and HITBSecConf 2017)
Stars: ✭ 178 (+313.95%)
Android RootkitA rootkit for Android. Based on "Android platform based linux kernel rootkit" from Phrack Issue 68
Stars: ✭ 167 (+288.37%)
MalwareRootkits | Backdoors | Sniffers | Virus | Ransomware | Steganography | Cryptography | Shellcodes | Webshells | Keylogger | Botnets | Worms | Other Network Tools
Stars: ✭ 156 (+262.79%)
Www.rootkit.comwww.rootkit.com users section mirror, sql database dump, and a few other files/rootkits.
Stars: ✭ 117 (+172.09%)
SpacecowWindows Rootkit written in Python
Stars: ✭ 81 (+88.37%)
Shadow Box For ArmShadow-Box: Lightweight and Practical Kernel Protector for ARM (Presented at BlackHat Asia 2018)
Stars: ✭ 64 (+48.84%)
SutekhAn example rootkit that gives a userland process root permissions
Stars: ✭ 62 (+44.19%)
WebshellWebshell && Backdoor Collection
Stars: ✭ 1,056 (+2355.81%)
Rootkits List DownloadThis is the list of all rootkits found so far on github and other sites.
Stars: ✭ 815 (+1795.35%)
VlanyLinux LD_PRELOAD rootkit (x86 and x86_64 architectures)
Stars: ✭ 804 (+1769.77%)
HiddenWindows driver with usermode interface which can hide objects of file-system and registry, protect processes and etc
Stars: ✭ 768 (+1686.05%)
DiamorphineLKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64)
Stars: ✭ 725 (+1586.05%)
RootkitLinux rootkit for Ubuntu 16.04 and 10.04 (Linux Kernels 4.4.0 and 2.6.32), both i386 and amd64
Stars: ✭ 601 (+1297.67%)
VegileThis tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process,unlimited your session in metasploit and transparent. Even when it killed, it will re-run again. There always be a procces which while run another process,So we can assume that this procces is unstopable like a Ghost in The Shell
Stars: ✭ 478 (+1011.63%)
HvmiHypervisor Memory Introspection Core Library
Stars: ✭ 438 (+918.6%)
Emp3r0rlinux post-exploitation framework made by linux user
Stars: ✭ 419 (+874.42%)
HideprocessA basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager
Stars: ✭ 329 (+665.12%)
FatherLD_PRELOAD rootkit
Stars: ✭ 59 (+37.21%)
lsrootkitRootkit Detector for UNIX
Stars: ✭ 53 (+23.26%)
superhideExample of hooking a linux systemcall
Stars: ✭ 48 (+11.63%)
rkorovald_preload userland rootkit
Stars: ✭ 34 (-20.93%)
raisinReverse shell and rootkit
Stars: ✭ 18 (-58.14%)
SMM-RootkitSMM rootkit similar to LoJax or MosaicRegressor
Stars: ✭ 44 (+2.33%)
NtSymbolResolve DOS MZ executable symbols at runtime
Stars: ✭ 78 (+81.4%)
SolarisA local LKM rootkit loader/dropper that lists available security mechanisms
Stars: ✭ 47 (+9.3%)
tor-rootkitA Python 3 standalone Windows 10 / Linux Rootkit using Tor.
Stars: ✭ 142 (+230.23%)
satan🔓 x86 Linux Kernel rootkit for Debian 9 (4.9.0-11-686-pae)
Stars: ✭ 31 (-27.91%)
VegileThis tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process,unlimited your session in metasploit and transparent. Even when it killed, it will re-run again. There always be a procces which while run another process,So we can assume that this procces is unstopable like a Ghost in The Shell
Stars: ✭ 601 (+1297.67%)