
रूटकिट व्यवहार, अवलोकनीय आर्टिफैक्ट्स और पहचान पर केंद्रित आक्रामक एवं रक्षात्मक लिनक्स कर्नेल सुरक्षा अनुसंधान।
यह रिपॉजिटरी एक ही सिक्के के दो पहलुओं को समेटे हुए है:
attack/ – प्रोजेक्ट RVBBIT, एक क्लासिक Linux कर्नेल रूटकिट जिसमें एम्बेडेड माइनर और नेटवर्क वर्म शामिल है।defense/ – RvbbitSafe, निर्णायक प्रतिकार उपाय जो RVBBIT के हर निशान का पता लगाता है, उसे निष्प्रभावी करता है, और हटा देता है।साथ मिलकर, ये आधुनिक Linux रूटकिट युद्ध पर व्यापक शैक्षिक संसाधन का निर्माण करते हैं।
cd attack
First, embed the XMRig payload (see attack/README.md)
./build.sh
Deploy rvbbit_installer on isolated test VM
Note: Detailed instructions on embedding payloads are in attack/README.md.
Deploy the Cure (Defense)
bash
cd defense
chmod +x install.sh
sudo ./install.sh
Documentation
Full technical whitepaper available in docs/whitepaper.md.
Disclaimer
This software is provided for authorized educational and defensive research only. Misuse is strictly prohibited and may violate computer crime laws. The authors assume no liability for improper use.
## Limitations
This is a learning prototype. It uses dated techniques, generates detectable telemetry, and will not evade modern EDRs or hypervisor integrity checks. Not intended for operational use.