
awesome-linux-attack-forensics-purplelabs
This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.
container-securitycurated-resourcesdigital-forensics+8

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…