rootkit
Here are 178 public repositories matching this topic...
awesome-linux-rootkits
-
Updated
Jul 8, 2022
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64)
-
Updated
Jan 19, 2022 - C
This is the list of all rootkits found so far on github and other sites.
-
Updated
Apr 28, 2022
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
-
Updated
Jun 21, 2022 - C++
Linux/Windows post-exploitation framework made by linux user
-
Updated
Jun 9, 2022 - Go
Linux rootkit for Ubuntu 16.04 and 10.04 (Linux Kernels 4.4.0 and 2.6.32), both i386 and amd64
-
Updated
Jul 5, 2019 - C
This tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process,unlimited your session in metasploit and transparent. Even when it killed, it will re-run again. There always be a procces which while run another process,So we can assume that this procces is unstopable like a Ghost in The Shell
-
Updated
Mar 9, 2020 - Shell
Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.
-
Updated
Mar 29, 2022 - C++
Hypervisor Memory Introspection Core Library
-
Updated
Feb 17, 2022 - C
Kernel rootkit, that lives inside the Windows registry values data
-
Updated
Oct 8, 2017 - C
A basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager
-
Updated
Mar 26, 2019 - C
Nidhogg is an all-in-one simple to use rootkit for red teams.
-
Updated
Jul 9, 2022 - C++
ebpfkit is a rootkit powered by eBPF
-
Updated
Aug 5, 2021 - C
Tool to generate a Linux kernel module for custom rules with Netfilter hooking. (block ports, Hidden mode, firewall functions)
-
Updated
Apr 24, 2022 - C
InfinityHookPro Win7 -> Win11 latest
-
Updated
Dec 7, 2021 - C++
Your interpreter isn’t safe anymore — The PHP module backdoor
-
Updated
Mar 25, 2019 - C
A rootkit for Android. Based on "Android platform based linux kernel rootkit" from Phrack Issue 68
-
Updated
Jun 15, 2015 - C
Shadow-Box: Lightweight and Practical Kernel Protector for x86 (Presented at BlackHat Asia 2017/2018, beVX 2018 and HITBSecConf 2017)
-
Updated
Jun 24, 2019 - C
A LKM rootkit for most newer kernel versions.
-
Updated
Sep 17, 2017 - C
A Python 3 standalone Windows 10 / Linux Rootkit using Tor.
-
Updated
Jun 9, 2022 - Python
a summary of linux rootkits published on GitHub
-
Updated
May 7, 2020
Improve this page
Add a description, image, and links to the rootkit topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the rootkit topic, visit your repo's landing page and select "manage topics."

Formed in 2009, the Archive Team (not to be confused with the archive.org Archive-It Team) is a rogue archivist collective dedicated to saving copies of rapidly dying or deleted websites for the sake of history and digital heritage. The group is 100% composed of volunteers and interested parties, and has expanded into a large amount of related projects for saving online and digital history.
