Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
awesome-linux-attack-forensics-purplelabs — 이 페이지는 고급 Linux 공격, 탐지 및 포렌식 기법과 도구에 대한 진행 중인 실무 연구의 결과물입니다. | Kitploit
도구/GitHubGitHub/cr0nx/awesome-linux-attack-forensics-purplelabs
Container SecurityMalware AnalysisDigital ForensicsPenetration TestingIntrusion DetectionPapers & ResearchLearning & EducationRed TeamingIncident Response

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
Curated Resources
Labs & Practice
GitHubcr0nx/awesome-linux-attack-forensics-purplelabs

awesome-linux-attack-forensics-purplelabs

이 페이지는 고급 Linux 공격, 탐지 및 포렌식 기법과 도구에 대한 진행 중인 실무 연구의 결과물입니다.

저장소 보기
34244733년 전Kitploit 검토 완료

awesome-linux-attack-forensics-purplelabs

이 페이지는 고급 Linux 공격, 탐지 및 포렌식 기법과 도구에 대한 지속적인 실무 연구의 결과입니다.

수년간 레드 팀과 블루 팀(red vs blue) 접근 방식을 실무에 적용해 온 결과, 아래 자료를 통해 Linux/Kubernetes 공격/탐지/DFIR 범위에 속한 프로젝트, 기법 및 전술의 규모를 확인할 수 있습니다.

이러한 모든 공격 기법과 도구는 (소스 코드 분석을 포함하여) 직접 테스트되었고, 다양한 계층(호스트/네트워크)에서 탐지되었으며, 소규모 핸즈온 랩 시나리오로 매핑되어 마침내 PurpleLabs Playground(https://edu.defensive-security.com/)의 일부가 되었습니다.

완전한 워크숍/교육 프로그램을 찾고 있다면, 아래 링크는 독특한 "Linux Attack and Live Forensics At Scale"(https://edu.defensive-security.com/linux-attack-live-forensics-at-scale) 교육 프로그램의 핵심입니다. 이것은 프레임워크로서의 역동적인 워크숍 프로그램을 만들기 위한 첫 단계로, 맞춤형 TTPS 전체 세트를 사용하여 Linux 공격자, 탐지 엔지니어, 포렌식 분석가의 역할을 동시에 수행할 수 있습니다! 또한 이 접근 방식을 통해 라이브 포렌식을 포함한 맞춤형 공격 경로, 탐지 엔지니어링 및 침해 대응 절차를 생성할 수도 있습니다.

평생 퍼플 팀링(Purple Teaming)!

오픈소스 SOC / IR

https://github.com/Cyb3rWard0g/HELK

https://github.com/Graylog2/graylog2-server

https://github.com/Velocidex/velociraptor

https://docs.velociraptor.app/exchange/

https://github.com/wazuh/wazuh

https://github.com/robcowart/elastiflow

https://github.com/arkime/arkime

https://github.com/osquery/osquery

https://github.com/TheHive-Project/TheHive

https://github.com/TheHive-Project/Cortex

https://github.com/Shuffle/Shuffle

https://github.com/dfir-iris/iris-web

https://github.com/MISP/MISP

https://jupyter.org/

https://github.com/OISF/suricata

https://github.com/zeek/zeek

https://github.com/SecurityRiskAdvisors/VECTR

https://github.com/archanchoudhury/SOC-OpenSource

Linux 및 Kubernetes 탐지 / 포렌식

https://github.com/sandflysecurity

https://github.com/lkrg-org/lkrg

https://github.com/Sysinternals/SysmonForLinux

https://github.com/volatilityfoundation/volatility

https://github.com/volatilityfoundation/community3

https://github.com/k1nd0ne/VolWeb

https://github.com/pathtofile/bpf-hookdetect

https://github.com/Exein-io/pulsar

https://github.com/ntop/libebpfflow

https://github.com/ehids/ehids-agent

https://github.com/falcosecurity/falco

https://github.com/aquasecurity/tracee

https://github.com/draios/sysdig

https://github.com/cilium/tetragon

https://github.com/gamemann/XDP-Firewall

https://github.com/linuxthor/rkbreaker

https://github.com/therealdreg/lsrootkit

https://github.com/linuxthor/rkspotter

https://github.com/kkamagui/shadow-box-for-x86

http://www.chkrootkit.org/

https://github.com/octarinesec/kube-scan

Linux 커널 공간 루트킷

https://github.com/lukasbalazik123/1337kit

https://github.com/f0rb1dd3n/Reptile

https://github.com/carloslack/KoviD

https://github.com/vkobel/linux-syscall-hook-rootkit

https://github.com/h3xduck/TripleCross

https://github.com/amir9339/ebpf_maps_hooking

https://github.com/milabs/kopycat

https://github.com/m0nad/Diamorphine

https://github.com/stdhu/kernel-inline-hook

https://github.com/ilammy/ftrace-hook

https://github.com/WeiJiLab/kernel-hook-framework

https://github.com/C24IO/Netfilter-Hooks-Simple.git

https://github.com/shubham0d/Immutable-file-linux

https://github.com/therealdreg/enyelkm

https://github.com/m0nad/Diamorphine

https://github.com/elfmaster/kprobe_rootkit

https://github.com/En14c/LilyOfTheValley

https://github.com/QuokkaLight/rkduck

https://github.com/a7vinx/liinux

https://github.com/mgrube/DragonKing

https://github.com/aidielse/Rootkits-Playground

https://github.com/cccssw/JynKbeast

https://github.com/hanj4096/wukong

https://github.com/mponcet/subversive

https://github.com/h3xduck/Umbra

https://github.com/ruckuus/kernel-abuse/tree/master/kbeast

https://github.com/CDuPlooy/Rootkit

https://github.com/jussihi/SMM-Rootkit

https://github.com/nnedkov/swiss_army_rootkit

https://github.com/spiderpig1297/kprochide

https://github.com/pathtofile/bad-bpf

https://github.com/cloudflare/ebpf_exporter

https://github.com/DavadDi/bpf_study

https://github.com/Esonhugh/sshd_backdoor

https://github.com/vrasneur/randkit

https://github.com/ricardomaraschini/ebpf-signals

https://github.com/bones-codes/the_colonel

https://github.com/PinkP4nther/Sutekh

https://github.com/spiderpig1297/kfile-over-icmp

https://github.com/dave4422/linux_rootkit

https://github.com/nurupo/rootkit

https://github.com/Nadharm/CoVirt

https://github.com/3intermute/loonix_syscall_hook

https://github.com/alfonmga/hiding-cryptominers-linux-rootkit

https://github.com/loneicewolf/linux-rootkits

https://github.com/yasindce1998/KubeDagger

https://github.com/loneicewolf/EXEC_LKM

https://github.com/deurzen/linux-rootkit

https://github.com/roggenbrot42/rkptum2013

https://github.com/DanielAvinoam/TheSubZeroProject

https://github.com/jermeyyy/rooty

https://github.com/NoviceLive/research-rootkit

https://github.com/aesophor/satan

https://github.com/Pratik32/linux_rkit

https://github.com/AlirezaChegini/kernel-based-keylogger-for-Linux

https://github.com/jordan9001/superhide

https://github.com/nccgroup/ebpf/tree/master/conjob

https://github.com/FlamingSpork/iptable_evil

https://github.com/ilee38/root-of-all-evil

https://github.com/milabs/lkrg-bypass

Linux 사용자 공간 루트킷 / 인젝터

https://github.com/ldpreload/Medusa

https://github.com/arget13/DDexec

https://github.com/mav8557/Father

https://github.com/yasukata/zpoline

https://github.com/dsnezhkov/zombieant

https://github.com/ulexec/SHELF-Loading

https://github.com/chokepoint/Jynx2

https://github.com/unix-thrust/beurk

https://github.com/cloudsec/brootkit

https://github.com/trimpsyw/adore-ng

https://github.com/rvillordo/libpreload

https://github.com/r00tkillah/HORSEPILL

https://github.com/elfmaster/skeksi_virus

https://github.com/elfmaster/linker_preloading_virus

https://github.com/nopn0p/rkorova

https://github.com/amir9339/Tcpdump-evasion

https://github.com/Paradoxis/PHP-Backdoor

https://github.com/ixty/mandibule

https://github.com/DavidBuchanan314/dlinject

https://github.com/guitmz/memrun

Linux C2 / 공격 에뮬레이션

https://github.com/BishopFox/sliver

https://github.com/facebookincubator/WEASEL

https://github.com/cyberark/kubesploit

https://github.com/controlplaneio/simulator

https://github.com/iagox86/dnscat2

https://github.com/rapid7/metasploit-framework

서적 / PDF / 문서

https://dl.acm.org/doi/fullHtml/10.1145/3545948.3545980 - Katana: Linux 메모리 스냅샷에 대한 강력하고 자동화된 바이너리 전용 포렌식 분석

https://www.crysys.hu/publications/files/setit/thesis_bme_Nemeth20bsc.pdf - 임베디드 IoT 기기에서 지속성 루트킷 구성 요소 탐지

https://raw.githubusercontent.com/h3xduck/TripleCross/master/docs/ebpf_offensive_rootkit_tfg.pdf - eBPF의 공격적 기능 분석 및 루트킷 구현

https://github.com/NinnOgTonic/Out-of-Sight-Out-of-Mind-Rootkit/blob/master/osom.pdf - Out-of-Sight-Out-of-Mind-Rootkit

https://pentera.io/blog/the-good-bad-and-compromisable-aspects-of-linux-ebpf/

https://www.welivesecurity.com/wp-content/uploads/2018/09/ESET-LoJax.pdf

https://vblocalhost.com/uploads/VB2021-Mechtinger-Kennedy.pdf

https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Fixing-A-Memory-Forensics-Blind-Spot-Linux-Kernel-Tracing-wp.pdf

https://i.blackhat.com/USA-20/Wednesday/us-20-Livelli-Decade-Of-The-RATs-Custom-Chinese-Linux-Rootkits-For-Everyone.pdf

https://www.vanbastelaer.com/publication/sabpf/sabpf.pdf

https://cormander.com/wp-content/uploads/2017/04/Distribution-Kernel-Security-Hardening.pdf

https://bibis.ir/science-books/information-technology/security/2022/Security-Observability-with-eBPF-by-Jed-Salazar_bibis.ir.pdf

https://isovalent.com/data/isovalent_security_observability.pdf

https://cs.brown.edu/~vpk/papers/ret2dir.sec14.pdf

https://www.iij.ad.jp/en/dev/iir/pdf/iir_vol45_focus_EN.pdf

https://www.brendangregg.com/Slides/BSidesSF2017_BPF_security_monitoring.pdf

https://apps.dtic.mil/sti/pdfs/AD1004190.pdf

http://jultika.oulu.fi/files/nbnfioulu-202004201485.pdf

https://i.blackhat.com/USA-22/Wednesday/US-22-Case-New-Memory-Forensics-Techniques-to-Defeat-Device-Monitoring-Malware-wp.pdf

https://i.blackhat.com/USA-22/Wednesday/US-22-Case-New-Memory-Forensics-Techniques-to-Defeat-Device-Monitoring-Malware.pdf

https://xgao-work.github.io/paper/dsn2021.pdf

도구 다운로드