Patching and hooking the Linux kernel with only a stripped Linux kernel image.
-
Updated
Feb 17, 2025 - C
8000
Patching and hooking the Linux kernel with only a stripped Linux kernel image.
system call hook for Linux
Inline syscalls made for MSVC supporting x64 and WOW64
System Call Hook for ARM64
Advanced process execution monitoring utility for linux (procmon like)
An example rootkit that gives a userland process root permissions
A system call interception tool
A Kernel module to break the kernel read-only to modify the syscall_table purpose (only in the Linux Arm64 6.6 Kernel test runs properly).
System call interception in linux-kernel module (kernel 2.6.34.7-61.fc13.x86_64)
HiddenGhost is an new solution for find system call table with support for 5.7x kernels +
Enumerate which window API calls are hooked by an EDR using inline patching technique
hodgepodge
Some custom Linux kernel modules written for own purposes or just as exercises
Kernel space drivers(LKM) to intecept, monitor and manipulate system calls in android systems
Add a description, image, and links to the syscall-hook topic page so that developers can more easily learn about it.
To associate your repository with the syscall-hook topic, visit your repo's landing page and select "manage topics."