reveng_rtkit
Diamorphine
reveng_rtkit | Diamorphine | |
---|---|---|
2 | 1 | |
206 | 1,669 | |
- | - | |
4.1 | 3.0 | |
8 months ago | 8 months ago | |
C | C | |
MIT License | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
reveng_rtkit
-
LKM based Rootkit: reveng_rtkit
LINK: https://github.com/reveng007/reveng_rtkit
- Introducing reveng_rtkit (LKM based Rootkit) targeting Linux OS capable of hiding itself, processes/implants and more. Most functionalities are same as famous diamorphine Rootkit, especially syscall interception, other functionalities are achieved differently, to bypass signature based antirootkits
Diamorphine
-
GitHub - jafarlihi/modreveal: Utility to find hidden Linux kernel modules
Looks like it can be used to detect the linked rootkit https://github.com/m0nad/Diamorphine
What are some alternatives?
libiio - A cross platform library for interfacing with local and remote Linux IIO devices
Dimorf - Dimorf is a ransomware using 256-bit AES with a self-destructing, randomly generated key for Linux OS´s
kdai - kdai(Kernel Dynamic ARP Inspection) is a linux kernel module to defend against arp cache poisoning
RecycledInjector - Native Syscalls Shellcode Injector
lkm-sandbox - Collection of Linux Kernel Modules and PoC to discover, learn and practice Linux Kernel Development
HiddenWall - Linux kernel module generator for Hidden firewall that follows the rules in the external YAML file.
SmmBackdoorNg - Updated version of System Management Mode backdoor for UEFI based platforms: old dog, new tricks
htkit - Information Gathering Simplified.
OctopusWAF - OctopusWAF is a WAF( Web application firewall) with high performance, made in C language and use libevent.
casper-fs - Casper-fs is a Custom Hidden Linux Kernel Module generator. Each module works in the file system to protect and hide secret files.
intel_nuc_led - Intel NUC7i[x]BN and NUC6CAY LED Control for Linux
skiboot - OPAL boot and runtime firmware for POWER