100 results for “topic:lkm”
The Linux Kernel Module Programming Guide (updated for 5.0+ kernels)
Stealthy Linux Kernel Rootkit for modern kernels (6x)
Utility to find hidden Linux kernel modules
A ring0 Loadable Kernel Module (Linux) for latest kernels 6.x
LKM rootkit for Linux x86 with the 2.6 kernel. It inserts salts inside system_call and sysenter_entry.
ModTracer Finds Hidden Linux Kernel Rootkits and then make visible again.
An example rootkit that gives a userland process root permissions
Cheat sheet to detect and remove linux kernel rootkit
A rootkit for Android.
Make an Linux Kernel rootkit visible again.
Tools to bypass flawed SELinux policies using the init_module system call
Attacking the cleanup_module function of a kernel module
A local LKM rootkit loader/dropper that lists available security mechanisms
Rust out-of-tree Linux Kernel Modules (LKMs) experimentation framework
Virtual Linux block device driver for simulating and performing I/O.
A quick LKM rootkit that executes a reverse TCP netcat shell with root privileges.
64-bit LKM Rootkit builder based on yaml prescription. Working on 5.15.5 kernel
Ftrace Based Linux Loadable Kernel Module Rootkit for Linux Kernel 5.x up to linux kernel 6.2 on x86_64, hides files, hides process, hides bind shell & reverse shell port, privilege escalation, cleans up logs and bash history during installation
「⚔️」Ring 0 Rootkit for Linux Kernels x86/x86_64 5.x/6.x
Kernel-space x86_64 Linux rootkit leveraging kprobes and ftrace for syscall hooking (hiding entries and reverse shell backdoor)
Wrong Boot (codename: wrong8007) is a programmable dead man's switch for Linux, living entirely in kernel space.
Reverse shell and rootkit
Linux Loadable Kernel Module Rootkit for Linux Kernel 5.x up to linux kernel 6.8 on x86_64, hides files, hides process, hides bind shell & reverse shell port, privilege escalation, cleans up logs and bash history during installation
kfile-over-icmp is an LKM for stealth sending of files over ICMP communication.
kunkillable is an LKM that makes userland processes unkillable.
A LKM (Loadable Kernel Module) to execute a command as root; I include a example of using netcat and a compiled(with source and steps on how to compile) reverse shell provided in C.
Linux kernel programming using loadable kernel modules (LKMs)
Very Easy Relative Backdoor Application
🔫 lkm module for emergency binary/script execution
PoC LKM to force run cleanup_module() on other LKMs