rootkit

Open-source projects categorized as rootkit

Top 23 rootkit Open-Source Projects

  • TitanHide

    Hiding kernel-driver for x86/x64.

  • TripleCross

    A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • Diamorphine

    LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

  • Nidhogg

    Nidhogg is an all-in-one simple to use rootkit.

  • Project mention: Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel. | /r/netsec | 2023-06-24

    This is not an exploit nor an example about how to write a driver and I didn't write anywhere about an exploit or how to write an driver. If you are looking for these kind of resources, feel free to check out my driver programming blog series "Lord of the Ring0" (and a talk that will be released soon! :) ): https://idov31.github.io/2022/07/14/lord-of-the-ring0-p1.html

  • r77-rootkit

    Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

  • RootKits-List-Download

    This is the list of all rootkits found so far on github and other sites.

  • emp3r0r

    Linux/Windows post-exploitation framework made by linux user

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  • Cronos-Rootkit

    Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

  • Chaos-Rootkit

    Now You See Me, Now You Don't

  • ebpfkit

    ebpfkit is a rootkit powered by eBPF

  • Black-Angel-Rootkit

    Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.

  • VectorKernel

    PoCs for Kernelmode rootkit techniques research.

  • Project mention: Windows APC Injection Driver updated to use less ring 3 memory in order to avoid detection | /r/blueteamsec | 2023-12-10
  • Jormungandr

    Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel. (by Idov31)

  • Project mention: Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel. | /r/RedSec | 2023-06-27
  • Kernel-Process-Hollowing

    Windows x64 kernel mode rootkit process hollowing POC.

  • Project mention: Kernel-Process-Hollowing: Windows x64 kernel mode rootkit process hollowing POC. | /r/blueteamsec | 2023-06-29
  • awesome-linux-rootkits

    a summary of linux rootkits published on GitHub

  • tor-rootkit

    A Python 3 standalone Windows 10 / Linux Rootkit using Tor.

  • Stuxnet-Source

    stuxnet Source & Binaries. ONLY FOR ACADEMICAL RESEARCH AND EDUCATIONAL PURPOSES! Includes: Source files, Binaries, PLC Samples,Fanny Added in another repo.

  • WSAAcceptBackdoor

    Winsock accept() Backdoor Implant.

  • ebpfkit-monitor

    ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits

  • arm64_silent_syscall_hook

    silent syscall hooking without modifying sys_call_table/handlers via patching exception handler

  • NtSymbol

    Resolve DOS MZ executable symbols at runtime

  • Qubes-VM-hardening

    Fend off malware at Qubes VM startup

  • Solaris

    A local LKM rootkit loader/dropper that lists available security mechanisms (by redcode-labs)

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

rootkit related posts

  • Windows APC Injection Driver updated to use less ring 3 memory in order to avoid detection

    1 project | /r/blueteamsec | 10 Dec 2023
  • Black-Angel-Rootkit: Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.

    1 project | /r/blueteamsec | 22 Mar 2023
  • TripleCross – Linux eBPF Rootkit

    1 project | news.ycombinator.com | 10 Jul 2022
  • GitHub - h3xduck/TripleCross: A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

    1 project | /r/devopsish | 7 Jul 2022
  • Show HN: TripleCross – A Linux eBPF rootkit with a C2 system and more

    1 project | news.ycombinator.com | 6 Jul 2022
  • Show HN: Credentials dumper for Linux using eBPF

    5 projects | news.ycombinator.com | 5 Jul 2022
  • TripleCross: A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

    1 project | /r/linux | 5 Jul 2022
  • A note from our sponsor - InfluxDB
    www.influxdata.com | 5 May 2024
    Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality. Learn more →

Index

What are some of the best open-source rootkit projects? This list will help you:

Project Stars
1 TitanHide 1,948
2 TripleCross 1,677
3 Diamorphine 1,664
4 Nidhogg 1,601
5 r77-rootkit 1,499
6 RootKits-List-Download 1,219
7 emp3r0r 1,209
8 Cronos-Rootkit 793
9 Chaos-Rootkit 687
10 ebpfkit 660
11 Black-Angel-Rootkit 565
12 VectorKernel 291
13 Jormungandr 210
14 Kernel-Process-Hollowing 176
15 awesome-linux-rootkits 159
16 tor-rootkit 156
17 Stuxnet-Source 151
18 WSAAcceptBackdoor 111
19 ebpfkit-monitor 110
20 arm64_silent_syscall_hook 95
21 NtSymbol 94
22 Qubes-VM-hardening 71
23 Solaris 53

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com