
r77-rootkit
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

Make an Linux Kernel rootkit visible again.

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

Linux kernel integrity monitor for detecting syscall hooking

Proof-of-concept that abuses Windows Enclave to implement anti-tamper and anti-cheat evasion techniques at the driver level.

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit…

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Kernel-Mode Rootkit Hunter

Detect Linux rootkits which use signals to elevate process privileges.