system call hook for Linux
-
Updated
Jan 6, 2025 - C
system call hook for Linux
Resources About Hooking. For All Platforms. Currently 300+ Tools And 600+ Posts.
Inline syscalls made for MSVC supporting x64 and WOW64
SysWhispers & HellsGate Successor, fully modular Indirect & Direct Syscall Framework - EDR/AV/AC Capability Platform
Rootkit for the blue team. Sophisticated and optimized LKM to detect and prevent malicious activity
Author of Project Adrishya a rootkit which use ftrace mechanism to hook syscall; (write this because God commanded me); work for both x86_64 and arm; CREDIT-(Oleksii Lozovskyi{ilammy})FOUNDER OF FTRACE HOOKING
The lazypoline syscall interposer
This project is no longer maintained. You should check out SledRE (https://github.com/sledre/sledre) which is the continuation of it.
Enumerate which window API calls are hooked by an EDR using inline patching technique
RKHUNTER LIVE is an immersive, interactive training platform for learning rootkit detection and malware forensics on Linux systems. Featuring a fully simulated rkhunter, chkrootkit, AIDE, and Lynis environment, this platform allows security professionals and students to practice identifying kernel rootkits, rootkits, userland rootkits🕵🏿.
Pedagogical project demonstrating basic syscalls hooks of a linux machine
fsh, a library provides a convenient and simple way to hook system calls using ftrace
Windows 11 compatible NtUserXxx syscall hook inside Win32k with PoC implementation and Usermode framework in both of C and C++
Add a description, image, and links to the syscall-hooking topic page so that developers can more easily learn about it.
To associate your repository with the syscall-hooking topic, visit your repo's landing page and select "manage topics."