
ssh-enum
This project explores whether modern OpenSSH reveals valid usernames through subtle response or timing differences. CVE-2016-6210 user enumeration…

This project explores whether modern OpenSSH reveals valid usernames through subtle response or timing differences. CVE-2016-6210 user enumeration…

Security issue in the hypervisor firmware of some older Qualcomm chipsets

PoC — origin validation error enabling Entra ID PRT SSO cookie exfiltration in linux-entra-sso (GHSA-g9vc-5j77-f2cm, CVE-2026-87005, CVSS 5.3).

A book-in-progress about the Linux kernel and its insides.

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Page Cache Side Channel Attacks (CVE-2019-5489) proof of concept for Linux

A deep dive into two critical Sudo vulnerabilities (CVE‑2025‑32463 & CVE‑2025‑32462) that enable local privilege escalation across major Linux…

In-depth analysis of CVE-2022-2590, a Linux kernel race condition in shared memory (shmem) enabling arbitrary write to read-only pages via…

A collection of links related to Linux kernel security and exploitation

Advanced Fuzzing Library - Slot your Fuzzer together in Rust! Scales across cores and machines. For Windows, Android, MacOS, Linux, no_std, ...

Tracking interesting Linux (and UNIX) malware. Send PRs

Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, including…

A Linux Host-based Intrusion Detection System based on eBPF.

Cross-platform C port of the Copy Fail Linux LPE (CVE-2026-31431). Disclosed 2026-04-29 by Theori / Xint.

Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.

Minimal machine architecture with LLVM compiler backend, Linux port, and virtual machine for creating self-contained software capsules that remain…

Learning Linux Binary Analysis, published by Packt

eBPF-based Linux rootkit detector using multi-channel cross-view analysis (sched_switch, NMI, /proc) to detect DKOM, tracepoint tampering, and…