process_injection_example
anticuckoo
process_injection_example | anticuckoo | |
---|---|---|
1 | 1 | |
5 | 284 | |
- | - | |
0.0 | 3.0 | |
about 3 years ago | 9 months ago | |
C | C | |
MIT License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
process_injection_example
-
Linux Remote Process Injection and Hooking Example - htop
I had a hard time finding a concrete Linux example of this online. Here's my attempt at a working example/tutorial: https://github.com/edouardpoitras/process_injection_example
anticuckoo
-
Security research homelab, made with <3
To avoid detection of something like a cuckoo I would use https://github.com/nsmfoo/antivmdetection and test it with https://github.com/therealdreg/anticuckoo and https://github.com/LordNoteworthy/al-khaser
What are some alternatives?
bhook - :fire: ByteHook is an Android PLT hook library which supports armeabi-v7a, arm64-v8a, x86 and x86_64.
Mhook - A Windows API hooking library
proxychains-ng - proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. the sf.net page is currently not updated, use releases from github release page instead.
cowrie - Cowrie SSH/Telnet Honeypot https://cowrie.readthedocs.io
Tripwire - Tripwire monitors ports and icmp to send the admin a message if somebody is scanning a machine that shouldn't be touched
al-khaser - Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
logalert - Monitor logs (or any text files) and send alerts on specific changes.
HideProcessHook - DLL that hooks the NtQuerySystemInformation API and hides a process name