2018-06-30 05:13:25 -04:00
|
|
|
# `awesome-linux-rootkits`
|
|
|
|
|
2018-06-30 05:48:34 -04:00
|
|
|
## :key: feature table
|
2018-06-30 05:13:25 -04:00
|
|
|
|
2018-06-30 15:01:40 -04:00
|
|
|
Environment:
|
2018-06-30 17:16:57 -04:00
|
|
|
- CPU architecture
|
2018-06-30 15:01:40 -04:00
|
|
|
- Kernel/User mode (or mixed)
|
|
|
|
|
|
|
|
Core capabilities:
|
|
|
|
- Persistency
|
2018-06-30 15:20:34 -04:00
|
|
|
- Management interface
|
2018-06-30 15:14:49 -04:00
|
|
|
|
|
|
|
Stealth capabilities:
|
2018-06-30 15:24:42 -04:00
|
|
|
- Detection evasion
|
2018-06-30 15:14:49 -04:00
|
|
|
- System logs cleaning (filtering)
|
2018-06-30 15:01:40 -04:00
|
|
|
|
|
|
|
Hiding stuff capabilities:
|
|
|
|
- Hiding of files and directories
|
|
|
|
- Hiding of processes and process trees
|
|
|
|
- Hiding of network connections and activity
|
|
|
|
- Hiding of process accounting information (like CPU usage)
|
|
|
|
|
|
|
|
Additional functions:
|
|
|
|
- Keylogger
|
|
|
|
- Backdoor/shell
|
2018-06-30 05:16:23 -04:00
|
|
|
|
2018-06-30 17:18:03 -04:00
|
|
|
## :see_no_evil: user mode rootkits
|
2018-06-30 05:16:23 -04:00
|
|
|
|
|
|
|
- https://github.com/mempodippy/vlany
|
|
|
|
|
|
|
|
Linux LD_PRELOAD rootkit (x86 and x86_64 architectures)
|
2018-06-30 05:46:39 -04:00
|
|
|
|
2018-06-30 17:18:03 -04:00
|
|
|
## :hear_no_evil: kernel mode rootkits
|
2018-06-30 05:46:39 -04:00
|
|
|
|
|
|
|
- https://github.com/f0rb1dd3n/Reptile
|
|
|
|
|
|
|
|
Reptile is a LKM rootkit written for evil purposes that runs on Linux kernel 2.6.x/3.x/4.x
|
2018-06-30 17:12:39 -04:00
|
|
|
|
2018-06-30 06:09:49 -04:00
|
|
|
- https://github.com/QuokkaLight/rkduck
|
|
|
|
|
|
|
|
rkduck - Rootkit for Linux v4
|
2018-06-30 09:26:13 -04:00
|
|
|
|
2018-06-30 17:16:57 -04:00
|
|
|
- https://github.com/mncoppola/suterusu
|
|
|
|
|
2018-06-30 17:27:30 -04:00
|
|
|
An LKM rootkit targeting Linux 2.6.x/3.x on x86, and ARM
|
2018-06-30 17:37:59 -04:00
|
|
|
|
|
|
|
- https://github.com/nurupo/rootkit
|
|
|
|
|
|
|
|
Linux rootkit for Ubuntu 16.04 and 10.04 (Linux Kernels 4.4.0 and 2.6.32), both i386 and amd64
|
2018-06-30 17:16:57 -04:00
|
|
|
|
2018-06-30 17:18:03 -04:00
|
|
|
- https://github.com/m0nad/Diamorphine :shit:
|
2018-06-30 17:12:39 -04:00
|
|
|
|
|
|
|
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x (x86 and x86_64)
|
2018-06-30 17:32:07 -04:00
|
|
|
|
|
|
|
- https://github.com/ivyl/rootkit :shit:
|
|
|
|
|
|
|
|
Sample Rootkit for Linux
|