Patching and hooking the Linux kernel with only a stripped Linux kernel image.
-
Updated
Sep 1, 2026 - C
Patching and hooking the Linux kernel with only a stripped Linux kernel image.
KASLD defeats Linux kernel KASLR from a local process — recovering the virtual and physical memory layout where a leak or side channel allows, and narrowing it to the smallest set of placements the evidence supports otherwise.
Utility to find hidden Linux kernel modules
Linux & Android Kernel Vulnerability research and exploitation
Minimal no-libc Linux x86_64 ELF PoC build for Copy Fail (CVE-2026-31431)
Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection
Advanced kernel-native security framework to disrupt and prevent DNS-based breaches including C2 channels and tunneling with zero data loss. Combines TC, Netfilter, raw socket interception, BPF maps, and ring buffers, runs entirely on eBPF in the Linux kernel. Integrates with deep learning for advanced intelligent EDR
Curated Linux LPE corpus — 28 modules from 2016 to 2026, with detection rules. One command, safest-first root: skeletonkey --auto --i-know
Windows BYOVD research on DCRCVDrv.sys and Alinubx.sys, reverse engineering their kernel primitives, IOCTL surfaces, and detection opportunities.
Offensive & defensive Linux kernel security research focused on rootkit behavior, observable artifacts and detection.
Project Chronos — eBPF/XDP covert timing-channel PoC for security research. Demonstrates kernel-level passive monitoring, IAT modulation, process masquerading & anti-forensics techniques. Built for Blue Team detection R&D.
Open-source hypervisor-based endpoint security. Ring -1 monitoring for Intel VT-x and AMD-V. Rootkit detection, DKOM, MSR guard, stealth EPT hooks.
Look for possible escape vectors from a container
Windows 10/11 x64 Kernel Analysis & Anti-Rootkit Toolkit
Hawkeye Community — official open-source edition of Hawkeye Lab. Windows kernel security research console. Download releases here.
DMA Lab - Hardware-level anti-cheat research, firmware configs, FPGA guides and PCILeech resources
An educational Secure Boot and Kernel Integrity Verification system demonstrating chain of trust, kernel signing, and protection against boot-level attacks using SHA-256 and RSA-2048.
A read-only Linux analyzer that maps kernel attack surface to the workloads using it and generates evidence-backed, reversible hardening plans.
A high-performance eBPF and C++20 kernel security engine for sub-microsecond process monitoring and execve execution blocking.
To associate your repository with the kernel-security topic, visit your repo's landing page and select "manage topics."