
Stuxnet
Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…

Educational reconstruction of the Stuxnet worm for malware analysis and defensive research. Includes modules for privilege escalation, rootkit…

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

Post-exploitation and evasion research toolkit for Linux.

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…

Live cryptojacking toolkit with CVE-2026-31431 LPE exploit, container escape, kernel rootkit, and XMRig Monero miner, captured from real attacks for…

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

PoCs for Kernelmode rootkit techniques research.

Detect Linux rootkits which use signals to elevate process privileges.

UEFI rootkit under development focusing on privilege escalation, C2 integration, and anti-EDR/AV evasion for real-world malware deployment.

Detects hidden Linux kernel rootkits (LKM-based) and restores their visibility using kernel-level inspection techniques for forensic analysis and…

Make an Linux Kernel rootkit visible again.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

SoulExtraction is a windows driver library for extracting cert information in windows drivers

Proof-of-concept that abuses Windows Enclave to implement anti-tamper and anti-cheat evasion techniques at the driver level.

Windows driver with usermode interface which can hide processes, file-system and registry objects, protect processes and etc

A Zeek protocol analyzer for the Facefish rootkit, based on Spicy.