system call hook for Linux
-
Updated
Jan 6, 2025 - C
system call hook for Linux
Resources About Hooking. For All Platforms. Currently 300+ Tools And 600+ Posts.
Inline syscalls made for MSVC supporting x64 and WOW64
SysWhispers & HellsGate Successor, fully modular Indirect & Direct Syscall Framework - EDR/AV/AC Capability Platform
Rootkit for the blue team. Sophisticated and optimized LKM to detect and prevent malicious activity
The lazypoline syscall interposer
Author of Project Adrishya a rootkit which use ftrace mechanism to hook syscall; (write this because God commanded me); work for both x86_64 and arm; CREDIT-(Oleksii Lozovskyi{ilammy})FOUNDER OF FTRACE HOOKING
This project is no longer maintained. You should check out SledRE (https://github.com/sledre/sledre) which is the continuation of it.
Enumerate which window API calls are hooked by an EDR using inline patching technique
Pedagogical project demonstrating basic syscalls hooks of a linux machine
RKHUNTER LIVE is an immersive, interactive training platform for learning rootkit detection and malware forensics on Linux systems. Featuring a fully simulated rkhunter, chkrootkit, AIDE, and Lynis environment, this platform allows security professionals and students to practice identifying kernel rootkits, rootkits, userland rootkits🕵🏿.
fsh, a library provides a convenient and simple way to hook system calls using ftrace
Windows 11 compatible NtUserXxx syscall hook inside Win32k with PoC implementation and Usermode framework in both of C and C++
Add a description, image, and links to the syscall-hooking topic page so that developers can more easily learn about it.
To associate your repository with the syscall-hooking topic, visit your repo's landing page and select "manage topics."