
Umbra
A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

A LKM rootkit targeting 4.x and 5.x kernel versions which opens a backdoor that can spawn a reverse shell to a remote host, launch malware and more.

Linux kernel module that grants root privileges, hides processes/files, and protects itself from unloading, designed for educational purposes on…

A rootkit for ubuntu-16.04.6 (Linux 4.4). Can hide a process, give root access and hide itself

LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

Stealthy Linux kernel rootkit (LKM) for 6.x kernels with advanced process/network hiding, privilege escalation, and comprehensive evasion of eBPF…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Windows rootkit for Intel x64 with 25+ features, demonstrating rootkit techniques compatible with all Windows 10 and Windows 11 versions.

A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.

PoCs for Kernelmode rootkit techniques research.

A Python 3 standalone Windows 10 / Linux Rootkit using Tor.

Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection

Make an Linux Kernel rootkit visible again.

Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.

Linux post-exploitation framework with a UEFI bootkit that persistently and stealthily loads a Rust-based kernel module rootkit on modern Linux…

Windows x64 kernel mode rootkit process hollowing POC.

Cronos is Windows 10/11 x64 ring 0 rootkit. Cronos is able to hide processes, protect and elevate them with token manipulation.

Black Angel is a Windows 11/10 x64 kernel mode rootkit. Rootkit can be loaded with enabled DSE while maintaining its full functionality.