rootkit topic
awesome-linux-rootkits
awesome-linux-rootkits
ebpfkit
ebpfkit is a rootkit powered by eBPF
vlany
Linux LD_PRELOAD rootkit (x86 and x86_64 architectures)
d0zer
Elf binary infector written in Go.
WindowsRegistryRootkit
Kernel rootkit, that lives inside the Windows registry values data
Cronos-Rootkit
Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.
Nidhogg
Nidhogg is an all-in-one simple to use rootkit.
r77-rootkit
Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
HideProcess
A basic Direct Kernel Object Manipulation rootkit that removes a process from the EPROCESS list, hiding it from the Task Manager
lkm-rootkit
A LKM rootkit for most newer kernel versions.