
rvbbit-arsenal
Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.
command-and-controldefensive-toolseducation+5
16

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.